Upstream information
Description
SUSE WebYaST before 1.2 0.2.63-0.6.1 allows remote attackers to modify the hosts list, and subsequently conduct man-in-the-middle attacks, via a crafted /host request on TCP port 4984.NVD CVSS v2 Base Score: 5.8 (AV:N/AC:M/Au:N/C:P/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 792712 SUSE Security Advisories:- SUSE-SU-2013:0053-1, published Wed, 23 Jan 2013 05:04:22 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Studio Standard Edition 1.2 |
| Builds SAT Patch Nr: 7236 |
| WebYaST 1.2 |
| Builds SAT Patch Nr: 7236 |
