The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to access or corrupt the RMT database.
References
Link | Resource |
---|---|
https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00068.html | Patch Third Party Advisory |
https://bugzilla.suse.com/show_bug.cgi?id=1117602 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2018-12-26 07:29
Updated : 2019-10-09 16:37
NVD link : CVE-2018-17957
Mitre link : CVE-2018-17957
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
suse
- repository_mirroring_tool