The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Suse_linux |
Suse |
* |
* |
References