VulnerabilityModified
CVE-2011-3177
The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network configuration files, like passwords for wireless networks.
HIGH 7.8EPSS 0.31%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network configuration files, like passwords for wireless networks.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- yast/yast2
- Source
- cve@mitre.org
References
- https://bugzilla.suse.com/show_bug.cgi?id=713661Issue Tracking, Third Party Advisory
- https://github.com/yast/yast-core/commit/7fe2e3df308b8b6a901cb2cfd60f398df53219deThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=713661Issue Tracking, Third Party Advisory
- https://github.com/yast/yast-core/commit/7fe2e3df308b8b6a901cb2cfd60f398df53219deThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.