The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to access or corrupt the RMT database.
References
| Link | Resource |
|---|---|
| https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00068.html | Patch Third Party Advisory |
| https://bugzilla.suse.com/show_bug.cgi?id=1117602 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2018-12-26 15:29
Updated : 2019-10-09 23:37
NVD link : CVE-2018-17957
Mitre link : CVE-2018-17957
JSON object : View
Products Affected
suse
- repository_mirroring_tool
CWE
CWE-287
Improper Authentication
