snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.
References
Configurations
Information
Published : 2014-06-17 08:55
Updated : 2015-03-11 18:59
NVD link : CVE-2014-4040
Mitre link : CVE-2014-4040
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
powerpc-utils_project
- powerpc-utils