CVE-2018-17957
Summary
| CVE | CVE-2018-17957 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-26 15:29:00 UTC |
| Updated | 2023-11-07 02:54:00 UTC |
| Description | The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to access or corrupt the RMT database. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Suse | Repository Mirroring Tool | All | All | All | All |
| Application | Suse | Repository Mirroring Tool | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] openSUSE-SU-2018:4272-1: important: Security update | CONFIRM | lists.opensuse.org | Patch, Third Party Advisory |
| Bug 1117602 – VUL-1: CVE-2018-17957: yast2-rmt: mysql password exposed in process list | CONFIRM | bugzilla.suse.com | Exploit, Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Fabian Schilling of SUSE
There are currently no legacy QID mappings associated with this CVE.