Vulnerability Description
The SUSE Audit Log Keeper daemon before 0.2.1-0.4.6.1 for SUSE Manager and Spacewalk uses world-readable permissions for /etc/auditlog-keeper.conf, which allows local users to obtain passwords by reading this file.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell | Suse Audit Log Keeper | <= 0.2.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00001.htmlVendor Advisory
- https://bugzilla.novell.com/771335
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00001.htmlVendor Advisory
- https://bugzilla.novell.com/771335
FAQ
What is CVE-2012-0421?
CVE-2012-0421 is a vulnerability with a CVSS score of 2.1 (LOW). The SUSE Audit Log Keeper daemon before 0.2.1-0.4.6.1 for SUSE Manager and Spacewalk uses world-readable permissions for /etc/auditlog-keeper.conf, which allows local users to obtain passwords by read...
How severe is CVE-2012-0421?
CVE-2012-0421 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-0421?
Check the references section above for vendor advisories and patch information. Affected products include: Novell Suse Audit Log Keeper.