PT-2012-4002 · Hostap · Hostapd

Vincent Danen

·

Published

2012-06-21

·

Updated

2013-04-19

·

CVE-2012-2389

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions hostapd versions prior to 1.0
Description The issue allows local users to potentially obtain sensitive information, such as credentials, due to the use of 0644 permissions for the /etc/hostapd/hostapd.conf file.
Recommendations For versions prior to 1.0, consider changing the permissions of the /etc/hostapd/hostapd.conf file to more restrictive settings to prevent unauthorized access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2389

Affected Products

Hostapd