Vulnerability Description
In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command line to tools used by yast2-samba-provision, allowing local attackers to read them in the process list
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensuse | Yast2-Samba-Provision | <= 1.0.1 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2018-17956?
CVE-2018-17956 is a vulnerability with a CVSS score of 7.8 (HIGH). In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command line to tools used by yast2-samba-provision, allowing local attackers to read them ...
How severe is CVE-2018-17956?
CVE-2018-17956 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17956?
Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Yast2-Samba-Provision.