CVE-2013-7042: Medium severity Novell Suse Lifecycle Management Server vulnerability
Published Dec 10, 2013
·Updated
SUSE Lifecycle Management Server (SLMS) before 1.3.7 uses world-readable permissions for the secret keys, which allows local users to gain privileges via unspecified vectors.
Affected Software
4 affected components
Novell Suse Lifecycle Management Server<=1.3
Novell Suse Lifecycle Management Server=1.0
Novell Suse Lifecycle Management Server=1.1
Novell Suse Lifecycle Management Server=1.2
Event History
Dec 10, 2013
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·04:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-7042?
CVE-2013-7042 is considered a moderate severity vulnerability due to world-readable permissions on secret keys.
2
How do I fix CVE-2013-7042?
To fix CVE-2013-7042, upgrade your SUSE Lifecycle Management Server to version 1.3.7 or later.
3
Who is affected by CVE-2013-7042?
CVE-2013-7042 affects all versions of SUSE Lifecycle Management Server prior to 1.3.7.
4
What are the potential impacts of CVE-2013-7042?
The potential impacts of CVE-2013-7042 include unauthorized access to secret keys, leading to privilege escalation for local users.
5
Is there a workaround for CVE-2013-7042?
There is no official workaround for CVE-2013-7042; updating to the fixed version is recommended.