VYPR

yast2-network

by SUSE S.A.

CVEs (2)

  • CVE-2011-3177HigSep 8, 2017
    risk 0.44cvss 7.8epss 0.00

    The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network configuration files, like passwords for wireless networks.

  • CVE-2012-0425Dec 2, 2013
    risk 0.00cvss epss 0.01

    LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows context-dependent attackers to obtain sensitive information by reading the (1) WIRELESS_WPA_PASSWORD or (2) WIRELESS_CLIENT_KEY_PASSWORD…