A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects: SUSE Linux Enterprise Server 15 munge versions prior to 0.5.13-4.3.1. openSUSE Factory munge versions prior to 0.5.13-6.1.
2020-01-23T16:15:11.760
2024-11-21T04:42:20.510
Modified
CVSSv3.1: 7.7 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | opensuse | munge | < 0.5.13-4.3.1 | Yes |
| Operating System | suse | suse_linux_enterprise_server | 15 | No |
| Application | opensuse | munge | < 0.5.13-6.1 | Yes |
| Application | opensuse | factory | - | No |