The supportconfig script in supportutils in SUSE Linux Enterprise 11 SP1 and 10 SP3 does not "disguise passwords" in configuration files, which has unknown impact and attack vectors.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/64690 | vdb entry |
http://secunia.com/advisories/42877 | third party advisory |
http://osvdb.org/70405 | vdb entry |
http://www.vupen.com/english/advisories/2011/0076 | vdb entry |