A Symbolic Link (Symlink) Following vulnerability in the...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Feb 8, 2023
Description
Published by the National Vulnerability Database
Jan 23, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Feb 8, 2023
A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects: SUSE SUSE Linux Enterprise Server 15 munge versions prior to 0.5.13-4.3.1. openSUSE Factory munge versions prior to 0.5.13-6.1.
References