Vulnerability Description
The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network configuration files, like passwords for wireless networks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yast | Yast2 | - |
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=713661Issue TrackingThird Party Advisory
- https://github.com/yast/yast-core/commit/7fe2e3df308b8b6a901cb2cfd60f398df53219dThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=713661Issue TrackingThird Party Advisory
- https://github.com/yast/yast-core/commit/7fe2e3df308b8b6a901cb2cfd60f398df53219dThird Party Advisory
FAQ
What is CVE-2011-3177?
CVE-2011-3177 is a vulnerability with a CVSS score of 7.8 (HIGH). The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network configuration files, like passwords for wireless networks...
How severe is CVE-2011-3177?
CVE-2011-3177 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-3177?
Check the references section above for vendor advisories and patch information. Affected products include: Yast Yast2.