Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-Id: <201205231021.26196.mweckbecker@suse.de>
Date: Wed, 23 May 2012 10:21:25 +0200
From: Matthias Weckbecker <mweckbecker@...e.de>
To: oss-security@...ts.openwall.com
Subject: CVE request(?): hostapd: improper file permissions of hostapd's config leaks credentials

Hi Kurt, 
Hi vendors,

not too critical in my opinion, but I think still worth to be at least 
mentioned briefly as other distros such as Fedora 16 were affected too:

https://bugzilla.novell.com/show_bug.cgi?id=740964

I'm not sure whether this issue should get a CVE, but in the past similar 
vulnerabilities got a CVE (e.g. CVE-2012-0863).

Thanks,
Matthias

-- 
Matthias Weckbecker, Junior Security Engineer, SUSE Security Team
SUSE LINUX Products GmbH, Maxfeldstr. 5, D-90409 Nuernberg, Germany
Tel: +49-911-74053-0;  http://suse.com/
SUSE LINUX Products GmbH, GF: Jeff Hawn, HRB 16746 (AG Nuernberg) 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.