PT-2020-8664 · Suse · Suse Linux Enterprise Server+3
Fabian Schilling
·
Published
2019-03-18
·
Updated
2024-06-15
·
CVE-2018-20105
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2
openSUSE Leap yast2-rmt versions prior to 1.2.2
Description:
A vulnerability in yast2-rmt allows local attackers to learn the password if they can access the log file. This issue is related to the inclusion of sensitive information in log files.
Recommendations:
For SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2, update to version 1.2.2 or later.
For openSUSE Leap yast2-rmt versions prior to 1.2.2, update to version 1.2.2 or later.
As a temporary workaround, consider restricting access to the log files to minimize the risk of exploitation.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse Linux Enterprise Server
Suse
Opensuse Leap
Yast2 Rmt