modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_uuid.map.
References
Link | Resource |
---|---|
http://lists.opensuse.org/opensuse-bugs/2015-06/msg02580.html | Mailing List Third Party Advisory |
http://lists.opensuse.org/opensuse-bugs/2015-06/msg02585.html | Mailing List Third Party Advisory |
http://lists.opensuse.org/opensuse-updates/2015-11/msg00098.html | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2015-11-19 12:59
Updated : 2020-10-05 12:06
NVD link : CVE-2015-0794
Mitre link : CVE-2015-0794
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
dracut_project
- dracut
opensuse
- opensuse