PT-2013-1492 · Suse · Suse Zypper+1
Publicado
2012-07-18
·
Atualizado
2013-12-03
·
CVE-2012-0420
CVSS v2.0
4.4
Média
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SUSE Zypper versions prior to 1.3.20
SUSE Zypper versions 1.6.x prior to 1.6.166
Description
The issue allows local users to create files in arbitrary directories, or possibly have unspecified other impact, via a pathname in the
ZYPP LOCKFILE ROOT environment variable.Recommendations
For SUSE Zypper versions prior to 1.3.20, update to version 1.3.20 or later.
For SUSE Zypper versions 1.6.x prior to 1.6.166, update to version 1.6.166 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Suse Zypper
Suse