Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-31998


A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root. This issue affects: SUSE Linux Enterprise Server 11-SP3 inn version inn-2.4.2-170.21.3.1 and prior versions. openSUSE Backports SLE-15-SP2 inn versions prior to 2.6.2. openSUSE Leap 15.2 inn versions prior to 2.6.2.


Published

2021-06-10T12:15:08.920

Last Modified

2024-11-21T06:06:40.980

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application opensuse inn ≤ 2.4.2-170.21.3.1 Yes
Operating System suse linux_enterprise_server 11 No
Application opensuse inn < 2.6.2 Yes
Application opensuse backports_sle 15.0 No
Operating System opensuse leap 15.2 No

References