The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.
Software | From | Fixed in |
---|---|---|
suse / suse_linux | - | - |