PT-2015-2764 · Dracut+1 · Dracut+1
Published
2015-11-19
·
Updated
2020-10-05
·
CVE-2015-0794
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
dracut versions prior to 037-17.30.1
Description
The issue is related to a symlink attack on
/tmp/dracut block uuid.map due to incorrect link resolution in the modules.d/90crypt/module-setup.sh component of the dracut package. This could allow a local attacker to have an unspecified impact, potentially compromising information security.Recommendations
For dracut versions prior to 037-17.30.1, update to version 037-17.30.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the
modules.d/90crypt/module-setup.sh component to minimize the risk of exploitation. Avoid using the /tmp/dracut block uuid.map file in sensitive operations until the issue is resolved.Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Dracut