Upstream information
Description
WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.NVD CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Novell/SUSE information
Novell Bugzilla entry: 591345, 598834 SUSE Security Advisories:- SUSE-SR:2010:014, published Mon, 02 Aug 2010 15:00:00 +0000
- SUSE-SR:2010:016, published Thu, 26 Aug 2010 11:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Webyast |
| webyast.x86 webyast.x86-64 SAT Patch Nr: 2616 |
| SUSE Webyast |
| webyast.x86-64 webyast.x86 SAT Patch Nr: 2408 |
