vulnerability

SUSE: CVE-2020-12831: SUSE Linux Security Advisory

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
May 13, 2020
Added
Feb 4, 2022
Modified
Feb 4, 2022

Description

** DISPUTED ** An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, the init script creates an empty config file with world-readable default permissions, leading to a possible information leak via tools/frr.in and tools/frrcommon.sh.in. NOTE: some parties consider this user error, not a vulnerability, because the permissions are under the control of the user before any sensitive information is present in the file.

Solution(s)

suse-upgrade-frrsuse-upgrade-frr-develsuse-upgrade-libfrr0suse-upgrade-libfrr_pb0suse-upgrade-libfrrcares0suse-upgrade-libfrrfpm_pb0suse-upgrade-libfrrgrpc_pb0suse-upgrade-libfrrospfapiclient0suse-upgrade-libfrrsnmp0suse-upgrade-libfrrzmq0suse-upgrade-libmlag_pb0
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.