libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users to obtain sensitive information by reading the file, as demonstrated by /tmp/libstorage-XXXXXX/pwdf. <a href"http://cwe.mitre.org/data/definitions/313.html">CWE-313: Cleartext Storage in a File or on Disk</a>
Publication date: Mon, 26 Sep 2016 20:59:00 +0000