PT-2013-1495 · Suse · Inst-Source-Utils+2
Publicado
2012-11-22
·
Atualizado
2018-10-30
·
CVE-2012-0427
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
yast2-add-on-creator in SUSE inst-source-utils versions 2008.11.26 through 2008.11.26-0.9.0
yast2-add-on-creator in SUSE inst-source-utils versions 2012.9.13 through 2012.9.13-0.8.0
Description
The issue allows local users to gain privileges via a crafted (1) file name or (2) directory name.
Recommendations
For yast2-add-on-creator in SUSE inst-source-utils versions 2008.11.26 through 2008.11.26-0.9.0, update to version 2008.11.26-0.9.1 or later.
For yast2-add-on-creator in SUSE inst-source-utils versions 2012.9.13 through 2012.9.13-0.8.0, update to version 2012.9.13-0.8.1 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Suse
Inst-Source-Utils
Yast2-Add-On-Creator