hostapd 'hostapd.conf' Configuration File Insecure File Permissions Vulnerability
BID:54093
Info
hostapd 'hostapd.conf' Configuration File Insecure File Permissions Vulnerability
| Bugtraq ID: | 54093 |
| Class: | Design Error |
| CVE: |
CVE-2012-2389 |
| Remote: | No |
| Local: | Yes |
| Published: | May 23 2012 12:00AM |
| Updated: | May 07 2015 05:04PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 |
| Not Vulnerable: | |
Discussion
hostapd 'hostapd.conf' Configuration File Insecure File Permissions Vulnerability
hostapd is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information such as credentials for PSKs and shared radius secrets. Information obtained may aid in further attacks.
hostapd is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information such as credentials for PSKs and shared radius secrets. Information obtained may aid in further attacks.
Exploit / POC
hostapd 'hostapd.conf' Configuration File Insecure File Permissions Vulnerability
Attackers can use readily available tools and standard commands to exploit this issue.
Attackers can use readily available tools and standard commands to exploit this issue.
Solution / Fix
hostapd 'hostapd.conf' Configuration File Insecure File Permissions Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2011 x86_64
Mandriva Linux Mandrake 2011
Solution:
Vendor updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2011 x86_64
-
Mandriva hostapd-0.7.3-2.3-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva hostapd-0.7.3-2.3-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
References
hostapd 'hostapd.conf' Configuration File Insecure File Permissions Vulnerability
References:
References: