SUSE WebYaST before 1.2 0.2.63-0.6.1 allows remote attackers to modify the hosts list, and subsequently conduct man-in-the-middle attacks, via a crafted /host request on TCP port 4984.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Webyast |
Suse |
1.2 (including) |
1.2 (including) |
References