Upstream information

CVE-2016-1601 at MITRE

Description

yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST installation when the profile does not contain inst-sys users, which might allow attackers to have unspecified impact via unknown vectors.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having critical severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 10
Vector AV:N/AC:L/Au:N/C:C/I:C/A:C
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
CVSS v3 Scores
  National Vulnerability Database
Base Score 9.8
Vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Access Vector Network
Access Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
SUSE Bugzilla entries: 973639 [RESOLVED / FIXED], 974220 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 12 SP1
  • yast2-users >= 3.1.41.3-9.1
Patchnames:
SUSE-SLE-DESKTOP-12-SP1-2016-669
SUSE Linux Enterprise Desktop 12 SP2
  • yast2-users >= 3.1.57-16.7
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA yast2-users
SUSE Linux Enterprise Desktop 12 SP3
  • yast2-users >= 3.2.11-1.47
Patchnames:
SUSE Linux Enterprise Desktop 12 SP3 GA yast2-users
SUSE Linux Enterprise Server 12 SP1
  • yast2-users >= 3.1.41.3-9.1
Patchnames:
SUSE-SLE-SERVER-12-SP1-2016-669
SUSE Linux Enterprise Server 12 SP2
  • yast2-users >= 3.1.57-16.7
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA yast2-users
SUSE Linux Enterprise Server 12 SP3
  • yast2-users >= 3.2.11-1.47
Patchnames:
SUSE Linux Enterprise Server 12 SP3 GA yast2-users
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • yast2-users >= 3.1.57-16.7
Patchnames:
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA yast2-users
SUSE Linux Enterprise Software Development Kit 12 SP1
  • yast2-users >= 3.1.41.3-9.1
  • yast2-users-devel-doc >= 3.1.41.3-9.1
Patchnames:
SUSE-SLE-SDK-12-SP1-2016-669
openSUSE Leap 42.1
  • yast2-users >= 3.1.41.3-10.1
  • yast2-users-debuginfo >= 3.1.41.3-10.1
  • yast2-users-debugsource >= 3.1.41.3-10.1
  • yast2-users-devel-doc >= 3.1.41.3-10.1
Patchnames:
openSUSE-2016-555
openSUSE Leap 42.2
  • yast2-users >= 3.1.58-2.1
Patchnames:
openSUSE Leap 42.2 GA yast2-users
openSUSE Leap 42.3
  • yast2-users >= 3.2.11-1.4
Patchnames:
openSUSE Leap 42.3 GA yast2-users
openSUSE Tumbleweed
  • yast2-users >= 3.2.6-1.1
Patchnames:
openSUSE Tumbleweed GA yast2-users


Status of this issue by product and package

Product(s) Source package State
SUSE Linux Enterprise Desktop 12 SP1 yast2-users Released
SUSE Linux Enterprise Desktop 12 SP2 yast2-users Not affected
SUSE Linux Enterprise SDK 12 SP1 yast2-users Released
SUSE Linux Enterprise Server 11 SP4 yast2-users Not affected
SUSE Linux Enterprise Server 12 SP1 yast2-users Released
SUSE Linux Enterprise Server 12 SP2 yast2-users Not affected