CVE-2016-5746
26.09.2016, 15:59
libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users to obtain sensitive information by reading the file, as demonstrated by /tmp/libstorage-XXXXXX/pwdf.Enginsight
Vendor | Product | Version |
---|---|---|
opensuse | libstorage | - |
opensuse | libstorage-ng | - |
yast | yast-storage | - |
opensuse | leap | 42.1 |
𝑥
= Vulnerable software versions
References