YaST is a system administration and installation framework for SUSE Linux distributions, with its vulnerability footprint concentrated in the storage-management and system-configuration components. The recurring signal centers on information-disclosure weaknesses, reflecting exposure risks inherent to administrative tools that handle sensitive system state and configuration data; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yast over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3177HIGH The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network configuration files, like passwords f | Sep 8, 2017 | 7.8 | 25 | NO | NO |
CVE-2016-5746MEDIUM libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users to obtain sensitiv | Sep 26, 2016 | 5.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yast.
Media articles that mention a CVE ID that affects a product developed by Yast — matched by CVE ID, not by vendor name.