First published: Tue Dec 14 1999(Updated: )
The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2000-0361 is considered low, mainly affecting local attackers.
To fix CVE-2000-0361, you should ensure that the .config file created by wvdial has proper permissions set to restrict access.
CVE-2000-0361 is a local information disclosure vulnerability due to improper file permissions.
Users in the dialout group can be affected by CVE-2000-0361 if they have access to the world-readable .config file.
Wvdial versions 1.4 and earlier are vulnerable to CVE-2000-0361.