A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects: SUSE Linux Enterprise Server 15 munge versions prior to 0.5.13-4.3.1. openSUSE Factory munge versions prior to 0.5.13-6.1.
2020-01-23T16:15:11.760
2024-11-21T04:42:20.510
Modified
CVSSv3.1: 7.7 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | opensuse | munge | < 0.5.13-4.3.1 | Yes |
Operating System | suse | suse_linux_enterprise_server | 15 | No |
Application | opensuse | munge | < 0.5.13-6.1 | Yes |
Application | opensuse | factory | - | No |