CVE-2013-3713: Infoleak
Published Jan 11, 2014
·Updated
The image creation configuration in aaabase before 16.26.1 for openSUSE 13.1 KDE adds the root user to the "users" group when installing from a live image, which allows local users to obtain sensitive information and possibly have other unspecified impacts, as demonstrated by reading /etc/shadow.
Affected Software
1 affected component
openSUSE openSUSE=13.1
Event History
Jan 11, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3713?
CVE-2013-3713 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2013-3713?
To fix CVE-2013-3713, ensure you update your openSUSE system to version 16.26.1 or later.
3
What are the potential impacts of CVE-2013-3713?
CVE-2013-3713 may allow local users to access sensitive information, including the contents of /etc/shadow.
4
Which versions of openSUSE are affected by CVE-2013-3713?
CVE-2013-3713 affects openSUSE version 13.1 prior to 16.26.1.
5
Is CVE-2013-3713 related to user group permissions?
Yes, CVE-2013-3713 involves the incorrect addition of the root user to the "users" group, affecting permissions.