SUSE WebYaST before 1.2 0.2.63-0.6.1 allows remote attackers to modify the hosts list, and subsequently conduct man-in-the-middle attacks, via a crafted /host request on TCP port 4984.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Webyast | Suse | 1.2 (including) | 1.2 (including) |