CVE-2012-0425: Infoleak
LanItems.ycp in savey2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows context-dependent attackers to obtain sensitive information by reading the (1) WIRELESSWPAPASSWORD or (2) WIRELESSCLIENTKEYPASSWORD field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0425?
CVE-2012-0425 is classified as a medium severity vulnerability due to the potential exposure of sensitive Wi-Fi credentials.
How do I fix CVE-2012-0425?
To remediate CVE-2012-0425, update to YaST2-network version 2.24.4 or later that addresses the issue of logging cleartext Wi-Fi credentials.
Which versions of SUSE are affected by CVE-2012-0425?
CVE-2012-0425 affects SUSE openSUSE 12.1 with YaST2-network versions prior to 2.24.4.
What information is exposed by CVE-2012-0425?
CVE-2012-0425 potentially exposes cleartext Wi-Fi credentials, including WIRELESS_WPA_PASSWORD and WIRELESS_CLIENT_KEY_PASSWORD.
Can context-dependent attackers exploit CVE-2012-0425?
Yes, context-dependent attackers can exploit CVE-2012-0425 by accessing the y2log log file to read the sensitive Wi-Fi credentials.