A Symbolic Link (Symlink) Following vulnerability in the packaging of munin in openSUSE Factory, Leap 15.1 allows local attackers to escalate from user munin to root. This issue affects: openSUSE Factory munin version 2.0.49-4.2 and prior versions. openSUSE Leap 15.1 munin version 2.0.40-lp151.1.1 and prior versions.
2020-01-24T11:15:11.563
2024-11-21T04:42:20.890
Modified
CVSSv3.1: 7.7 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | opensuse | munin | ≤ 2.0.49-4.2 | Yes |
Application | opensuse | factory | - | No |
Application | suse | munin | ≤ 2.0.40-lp151.1.1 | Yes |
Operating System | opensuse | leap | 15.1 | No |