Unprotected Transport of Credentials in yast2-samba-provision - CVE-2018-17956

 

Unprotected Transport of Credentials in yast2-samba-provision - CVE-2018-17956

Published: September 11, 2022


Vulnerability identifier: #VU67162
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17956
CWE-ID: CWE-523
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to the password for samba shares is provided on the command line to tools used by yast2-samba-provision. A local user can view the list of running processes and obtain the password in clear text.


Affected software

yast2-samba-provision
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap

How to mitigate CVE-2018-17956

Install updates from vendor's website.

yast2-samba-provision - update to 1.0.5-150400.9.3.3

External References

Related Security Bulletins