PT-2011-2363 · Suse · Aaa Base
Published
2011-04-01
·
Updated
2024-06-15
·
CVE-2011-0461
CVSS v2.0
6.3
Medium
| Vector | AV:L/AC:M/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
aaa base versions prior to 11.2-43.48.1 in SUSE openSUSE 11.2
aaa base versions prior to 11.3-8.7.1 in openSUSE 11.3
Description
The issue allows local users to overwrite arbitrary files via a symlink attack on
/dev/shm/mtab. This is due to a flaw in the /etc/init.d/boot.localfs script in the aaa base package.Recommendations
For aaa base versions prior to 11.2-43.48.1 in SUSE openSUSE 11.2, update to version 11.2-43.48.1 or later.
For aaa base versions prior to 11.3-8.7.1 in openSUSE 11.3, update to version 11.3-8.7.1 or later.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aaa Base