PT-2022-15194 · Suse+1 · Opensuse+1

Matthias Gerstner

·

Published

2022-01-17

·

Updated

2023-04-14

·

CVE-2022-21944

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0 openSUSE Factory watchman versions prior to 4.9.0-9.1
Description A UNIX Symbolic Link (Symlink) Following issue in the systemd service file for watchman allows local attackers to escalate to root.
Recommendations For openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0, update to version 4.9.0 or later. For openSUSE Factory watchman versions prior to 4.9.0-9.1, update to version 4.9.0-9.1 or later.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-21944
OPENSUSE-SU-2022:0016-1
OPENSUSE-SU-2024:11728-1

Affected Products

Opensuse
Watchman