Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows context-dependent attackers to obtain sensitive information by reading the (1) WIRELESS_WPA_PASSWORD or (2) WIRELESS_CLIENT_KEY_PASSWORD field.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Novell SUSE YaST 信息泄露漏洞
Vulnerability Description
Novell SUSE YaST(Yet another Setup Tool)是美国Novell公司的一套以RPM为基础的openSUSE和SUSE Linux Enterprise操作系统的安装与配置工具。该工具可配置系统的硬件、网络、服务等。 SUSE YaST中的yast2-network 2.24.4之前的版本中的save_y2logs命令中的LanItems.ycp文件存在信息泄露漏洞,该漏洞源于y2log日志文件中存储Wi-Fi明文凭证。攻击者可通过读取WIRELESS_WPA_PASSWO
CVSS Information
N/A
Vulnerability Type
N/A