vendor:
SuSE Linux
by:
Nash Leon
7.2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: SuSE Linux
Affected Version From: SuSE 8.2
Affected Version To: SuSE 8.2
Patch Exists: NO
Related CWE: N/A
CPE: o:suse:suse_linux:8.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2004
SuSEconfig.vmware Symbolic Link
A problem exists in the SuSEWM configuration file used by SuSEConfig. Because of this, it may be possible for a local attacker to gain elevated privileges. This exploit creates a symbolic link in the /tmp directory which can be used to gain root privileges when Yast2 is run.
Mitigation:
Ensure that the SuSEWM configuration file is properly configured and that the permissions are set correctly.