LWN.net Logo

WebYaST: information disclosure

Package(s):WebYaST CVE #(s):CVE-2012-0435
Created:January 23, 2013 Updated:January 23, 2013
Description: From the SUSE advisory:

The hosts list used by WebYaST for connecting to it's back end part was modifiable allowing to point to a malicious website which then could access all values sent by WebYaST.

The /host configuration path was removed to fix this issue.

Alerts:
SUSE SUSE-SU-2013:0053-1 2013-01-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds