SOSreport stores the md5 hash of the GRUB bootloader password in an archive, which allows local users to obtain sensitive information by reading the archive. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0246