libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users to obtain sensitive information by reading the file, as demonstrated by /tmp/libstorage-XXXXXX/pwdf.
2016-09-26T15:59:00.140
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 5.1 (MEDIUM)
AV:L/AC:H/Au:N/C:P/I:N/A:N
1.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | opensuse | libstorage | - | Yes |
Application | opensuse | libstorage-ng | - | Yes |
Application | yast | yast-storage | - | Yes |
Operating System | opensuse | leap | 42.1 | Yes |