LWN.net Logo

SUSE Manager: multiple vulnerabilities

Package(s):SUSE Manager CVE #(s):CVE-2009-4139 CVE-2011-1594
Created:June 20, 2011 Updated:June 22, 2011
Description: From the SUSE advisory:

CVE-2009-4139: A cross-site request forgery (CSRF) attack can be used to execute web-actions within the SUSE Manager web user interface with the privileges of the attacked user.

CVE-2011-1594: Open Redirect bug at the login page (Phishing)

  • using secure SSL ciphersuites only
  • added a "password strength meter"
Alerts:
SUSE SUSE-SU-2011:0653-1 2011-06-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds