First published: Wed Jan 12 2011(Updated: )
The supportconfig script in supportutils in SUSE Linux Enterprise 11 SP1 and 10 SP3 does not "disguise passwords" in configuration files, which has unknown impact and attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =10-sp3 | |
SUSE Linux | =11-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3912 has an unknown severity level due to the lack of detailed information regarding its impact.
To mitigate CVE-2010-3912, ensure that the supportconfig script does not store plain text passwords in configuration files.
CVE-2010-3912 affects SUSE Linux Enterprise 11 SP1 and SUSE Linux Enterprise 10 SP3.
The risks associated with CVE-2010-3912 include the potential exposure of sensitive passwords in configuration files.
A recommended workaround for CVE-2010-3912 is to manually review and secure any configuration files that may contain plaintext passwords.