PT-2015-2764 · Dracut+1 · Dracut+1

Publicado

2015-11-19

·

Atualizado

2020-10-05

·

CVE-2015-0794

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions dracut versions prior to 037-17.30.1
Description The issue is related to a symlink attack on /tmp/dracut block uuid.map due to incorrect link resolution in the modules.d/90crypt/module-setup.sh component of the dracut package. This could allow a local attacker to have an unspecified impact, potentially compromising information security.
Recommendations For dracut versions prior to 037-17.30.1, update to version 037-17.30.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the modules.d/90crypt/module-setup.sh component to minimize the risk of exploitation. Avoid using the /tmp/dracut block uuid.map file in sensitive operations until the issue is resolved.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-12129
CVE-2015-0794
SUSE-SU-2015:2065-1
SUSE-SU-2015_2065-1

Produtos afetados

Suse
Dracut