CVE-2018-17956: Password exposed in process listing
Published Mar 15, 2019
·Updated
In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command line to tools used by yast2-samba-provision, allowing local attackers to read them in the process list
Affected Software
1 affected component
openSUSE Yast2-samba-provision<=1.0.1
Event History
Mar 15, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-17956?
CVE-2018-17956 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2018-17956?
To fix CVE-2018-17956, upgrade yast2-samba-provision to version 1.0.2 or later.
3
Who is affected by CVE-2018-17956?
Users of yast2-samba-provision version 1.0.1 and earlier on OpenSUSE are affected by CVE-2018-17956.
4
What type of attack does CVE-2018-17956 enable?
CVE-2018-17956 allows local attackers to read Samba share passwords from the command line in the process list.
5
Is CVE-2018-17956 a local or remote vulnerability?
CVE-2018-17956 is a local vulnerability, requiring access to the command line of the affected system.