CVE-2022-31252
Summary
| CVE | CVE-2022-31252 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-06 18:16:00 UTC |
| Updated | 2022-11-07 20:20:00 UTC |
| Description | A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local attackers with access to a group what can write to a location included in the path to a privileged binary to influence path resolution. This issue affects: SUSE Linux Enterprise Server 12-SP5 permissions versions prior to 20170707. openSUSE Leap 15.3 permissions versions prior to 20200127. openSUSE Leap 15.4 permissions versions prior to 20201225. openSUSE Leap Micro 5.2 permissions versions prior to 20181225. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Opensuse | Leap | 15.3 | All | All | All |
| Operating System | Opensuse | Leap | 15.4 | All | All | All |
| Operating System | Opensuse | Leap Micro | 5.2 | All | All | All |
| Operating System | Suse | Linux Enterprise Server | 12 | sp5 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cve-website | MISC | www.cve.org | |
| Bug 1203018 – VUL-0: CVE-2022-31252: permissions: chkstat does not check for group-writable parent directories or target files in safeOpen() | CONFIRM | bugzilla.suse.com | |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Martin Wilck from SUSE
Legacy QID Mappings
- 752603 OpenSUSE Security Update for permissions (openSUSE-SU-2022:10128-1)
- 752607 SUSE Enterprise Linux Security Update for permissions (SUSE-SU-2022:3353-1)
- 752616 SUSE Enterprise Linux Security Update for permissions (SUSE-SU-2022:3394-1)
- 752617 SUSE Enterprise Linux Security Update for permissions (SUSE-SU-2022:3382-1)