oss-sec mailing list archives

CVE request(?): hostapd: improper file permissions of hostapd's config leaks credentials


From: Matthias Weckbecker <mweckbecker () suse de>
Date: Wed, 23 May 2012 10:21:25 +0200

Hi Kurt, 
Hi vendors,

not too critical in my opinion, but I think still worth to be at least 
mentioned briefly as other distros such as Fedora 16 were affected too:

https://bugzilla.novell.com/show_bug.cgi?id=740964

I'm not sure whether this issue should get a CVE, but in the past similar 
vulnerabilities got a CVE (e.g. CVE-2012-0863).

Thanks,
Matthias

-- 
Matthias Weckbecker, Junior Security Engineer, SUSE Security Team
SUSE LINUX Products GmbH, Maxfeldstr. 5, D-90409 Nuernberg, Germany
Tel: +49-911-74053-0;  http://suse.com/
SUSE LINUX Products GmbH, GF: Jeff Hawn, HRB 16746 (AG Nuernberg) 


Current thread: