Vulnerability Name: | CVE-2000-0361 (CCN-4172) | ||||||||
Assigned: | 1999-12-14 | ||||||||
Published: | 1999-12-14 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2000-0361 Source: SUSE Type: UNKNOWN 19991214 Security hole in wvdial <= 1.4 Source: CCN Type: OSVDB ID: 7693 wvdial PPP wvdial.lxdialog .config Login Credential Disclosure Source: CCN Type: SuSE Security Announcement #35 wvdial <= 1.4 Source: XF Type: UNKNOWN wvdial-gain-dialup-info(4172) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |