PT-2020-8664 · Suse · Suse Linux Enterprise Server+3

Fabian Schilling

·

Published

2019-03-18

·

Updated

2024-06-15

·

CVE-2018-20105

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2 openSUSE Leap yast2-rmt versions prior to 1.2.2
Description: A vulnerability in yast2-rmt allows local attackers to learn the password if they can access the log file. This issue is related to the inclusion of sensitive information in log files.
Recommendations: For SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2, update to version 1.2.2 or later. For openSUSE Leap yast2-rmt versions prior to 1.2.2, update to version 1.2.2 or later. As a temporary workaround, consider restricting access to the log files to minimize the risk of exploitation.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20105
OPENSUSE-SU-2019:1089-1
OPENSUSE-SU-2019_1089-1
OPENSUSE-SU-2020:0253-1
OPENSUSE-SU-2020:0320-1
OPENSUSE-SU-2020_0253-1
OPENSUSE-SU-2020_0320-1
OPENSUSE-SU-2024:11534-1
SUSE-SU-2019:0629-1
SUSE-SU-2019_0629-1
SUSE-SU-2020:0578-1
SUSE-SU-2020_0578-1

Affected Products

Suse Linux Enterprise Server
Suse
Opensuse Leap
Yast2 Rmt