In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems without symlink protection
2019-03-15T20:29:00.557
2024-11-21T03:55:16.480
Modified
CVSSv3.0: 2.2 (LOW)
AV:L/AC:L/Au:N/C:N/I:P/A:P
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | opensuse | yast2-multipath | < 4.1.1 | Yes |