PT-2013-1495 · Suse · Inst-Source-Utils+2

Published

2012-11-22

·

Updated

2018-10-30

·

CVE-2012-0427

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions yast2-add-on-creator in SUSE inst-source-utils versions 2008.11.26 through 2008.11.26-0.9.0 yast2-add-on-creator in SUSE inst-source-utils versions 2012.9.13 through 2012.9.13-0.8.0
Description The issue allows local users to gain privileges via a crafted (1) file name or (2) directory name.
Recommendations For yast2-add-on-creator in SUSE inst-source-utils versions 2008.11.26 through 2008.11.26-0.9.0, update to version 2008.11.26-0.9.1 or later. For yast2-add-on-creator in SUSE inst-source-utils versions 2012.9.13 through 2012.9.13-0.8.0, update to version 2012.9.13-0.8.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-0427
SUSE-SU-2012_1529-1

Affected Products

Suse
Inst-Source-Utils
Yast2-Add-On-Creator