A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root. This issue affects: SUSE Linux Enterprise Server 11-SP3 inn version inn-2.4.2-170.21.3.1 and prior versions. openSUSE Backports SLE-15-SP2 inn versions prior to 2.6.2. openSUSE Leap 15.2 inn versions prior to 2.6.2.
2021-06-10T12:15:08.920
2024-11-21T06:06:40.980
Modified
CVSSv3.1: 6.8 (MEDIUM)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | opensuse | inn | ≤ 2.4.2-170.21.3.1 | Yes |
Operating System | suse | linux_enterprise_server | 11 | No |
Application | opensuse | inn | < 2.6.2 | Yes |
Application | opensuse | backports_sle | 15.0 | No |
Operating System | opensuse | leap | 15.2 | No |