The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
2018-06-08T17:29:00.490
2024-11-21T02:11:39.127
Modified
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | opensuse | opensuse | 13.2 | Yes |
| Application | mdadm_project | mdadm | < 3.3.3 | Yes |