|
|
| |
|
| |
WebYaST: information disclosure
| Package(s): | WebYaST |
CVE #(s): | CVE-2012-0435
|
| Created: | January 23, 2013 |
Updated: | January 23, 2013 |
| Description: |
From the SUSE advisory:
The hosts list used by WebYaST for connecting to it's back
end part was modifiable allowing to point to a malicious
website which then could access all values sent by WebYaST.
The /host configuration path was removed to fix this issue. |
| Alerts: |
|
( Log in to post comments)
|
|
|