CVE-2013-3713

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
11/01/2014
Last modified:
11/04/2025

Description

The image creation configuration in aaa_base before 16.26.1 for openSUSE 13.1 KDE adds the root user to the "users" group when installing from a live image, which allows local users to obtain sensitive information and possibly have other unspecified impacts, as demonstrated by reading /etc/shadow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*