SUSE YaST WebYaST Appliance Pre-Installed Image Default Secret Key Security Bypass Vulnerability
BID:42128
Info
SUSE YaST WebYaST Appliance Pre-Installed Image Default Secret Key Security Bypass Vulnerability
| Bugtraq ID: | 42128 |
| Class: | Design Error |
| CVE: |
CVE-2010-1507 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2010 12:00AM |
| Updated: | Sep 01 2010 06:36PM |
| Credit: | SuSE |
| Vulnerable: |
SuSE YaST2 SuSE SUSE Linux Enterprise 11 |
| Not Vulnerable: | |
Discussion
SUSE YaST WebYaST Appliance Pre-Installed Image Default Secret Key Security Bypass Vulnerability
WebYaST is affected by a vulnerability that allows attackers to bypass security.
An attacker can exploit this issue to bypass certain security restrictions and gain unauthorized access to affected computers. Successfully exploiting this issue may lead to further attacks.
Versions of WebYaST on appliances preloaded with SLE 11 are vulnerable.
WebYaST is affected by a vulnerability that allows attackers to bypass security.
An attacker can exploit this issue to bypass certain security restrictions and gain unauthorized access to affected computers. Successfully exploiting this issue may lead to further attacks.
Versions of WebYaST on appliances preloaded with SLE 11 are vulnerable.
Exploit / POC
SUSE YaST WebYaST Appliance Pre-Installed Image Default Secret Key Security Bypass Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
SUSE YaST WebYaST Appliance Pre-Installed Image Default Secret Key Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
SUSE YaST WebYaST Appliance Pre-Installed Image Default Secret Key Security Bypass Vulnerability
References:
References:
- YaST Homepage (SuSE)