PT-2006-3672 · Ximian+2 · Redcarpet+2

Published

2006-06-01

·

Updated

2018-10-18

·

CVE-2006-2752

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Novell Linux Desktop version 9 SUSE SLES version 9
Description The issue concerns the RedCarpet /etc/ximian/rcd.conf configuration file, which has world-readable permissions. This allows attackers to obtain the rc (RedCarpet) password.
Recommendations For Novell Linux Desktop version 9, restrict access to the /etc/ximian/rcd.conf file to prevent unauthorized reading of the rc password. For SUSE SLES version 9, change the permissions of the /etc/ximian/rcd.conf file to prevent world-readable access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2752

Affected Products

Novell Linux Desktop
Redcarpet
Suse Sles