PT-2021-3960 · Suse · Suse Linux Enterprise Server 15 Sp1+3

Matthias Gerstner

·

Published

2021-01-18

·

Updated

2024-06-15

·

CVE-2021-32000

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise Server 12 SP3 clone-master-clean-up versions 1.6-4.6.1 and prior versions SUSE Linux Enterprise Server 15 SP1 clone-master-clean-up versions 1.6-3.9.1 and prior versions openSUSE Factory clone-master-clean-up versions 1.6-1.4 and prior versions
Description A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up allows local attackers to delete arbitrary files. This issue is related to errors in handling links, which can be exploited by an attacker to remove files.
Recommendations For SUSE Linux Enterprise Server 12 SP3 clone-master-clean-up versions 1.6-4.6.1 and prior versions, update to a version later than 1.6-4.6.1 to resolve the issue. For SUSE Linux Enterprise Server 15 SP1 clone-master-clean-up versions 1.6-3.9.1 and prior versions, update to a version later than 1.6-3.9.1 to resolve the issue. For openSUSE Factory clone-master-clean-up versions 1.6-1.4 and prior versions, update to a version later than 1.6-1.4 to resolve the issue. As a temporary workaround, consider restricting access to the clone-master-clean-up.sh script until a patch is available.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04479
CVE-2021-32000
OPENSUSE-SU-2022_3667-1
OPENSUSE-SU-2024:12840-1
SUSE-SU-2022:3667-1
SUSE-SU-2022:3674-1
SUSE-SU-2022_3667-1
SUSE-SU-2022_3674-1

Affected Products

Suse Linux Enterprise Server 12 Sp3
Suse Linux Enterprise Server 15 Sp1
Suse
Opensuse Factory