libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users to obtain sensitive information by reading the file, as demonstrated by /tmp/libstorage-XXXXXX/pwdf.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2016-09-26 15:59
Updated : 2024-02-04 18:53
NVD link : CVE-2016-5746
Mitre link : CVE-2016-5746
CVE.ORG link : CVE-2016-5746
JSON object : View
Products Affected
yast
- yast-storage
opensuse
- libstorage
- libstorage-ng
- leap
CWE