First published: Wed May 23 2012(Updated: )
hostapd 0.7.3, and possibly other versions before 1.0, uses 0644 permissions for /etc/hostapd/hostapd.conf, which might allow local users to obtain sensitive information such as credentials.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
hostapd | =0.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2389 is classified as a moderate severity vulnerability due to the risk of local users accessing sensitive information.
To fix CVE-2012-2389, change the permissions of /etc/hostapd/hostapd.conf to a more secure setting, such as 0600.
CVE-2012-2389 affects hostapd versions prior to 1.0, including version 0.7.3.
CVE-2012-2389 may expose sensitive credentials stored in /etc/hostapd/hostapd.conf to local users.
CVE-2012-2389 is primarily associated with hostapd implementations on Linux-based systems.