opensuse-updater Symbolic Link Local Information Disclosure Vulnerability
BID:29608
Info
opensuse-updater Symbolic Link Local Information Disclosure Vulnerability
| Bugtraq ID: | 29608 |
| Class: | Design Error |
| CVE: |
CVE-2008-2389 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 09 2008 12:00AM |
| Updated: | Jun 09 2008 07:32PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SuSE opensuse-updater 0 S.u.S.E. openSUSE 10.2 |
| Not Vulnerable: | |
Discussion
opensuse-updater Symbolic Link Local Information Disclosure Vulnerability
The 'opensuse-updater' program is prone to a local information-disclosure vulnerability.
A local attacker can exploit this issue to obtain sensitive information that may lead to further attacks.
This issue affects opensuse-updater running on openSUSE 10.2.
The 'opensuse-updater' program is prone to a local information-disclosure vulnerability.
A local attacker can exploit this issue to obtain sensitive information that may lead to further attacks.
This issue affects opensuse-updater running on openSUSE 10.2.
Exploit / POC
opensuse-updater Symbolic Link Local Information Disclosure Vulnerability
An attacker uses readily available commands to exploit this issue.
An attacker uses readily available commands to exploit this issue.
Solution / Fix
opensuse-updater Symbolic Link Local Information Disclosure Vulnerability
Solution:
SUSE has released an advisory (SUSE-SR:2008:012) and fixes for this issue. Please see the referenced advisory for details.
Solution:
SUSE has released an advisory (SUSE-SR:2008:012) and fixes for this issue. Please see the referenced advisory for details.
References
opensuse-updater Symbolic Link Local Information Disclosure Vulnerability
References:
References:
- opensuse-updater Homepage (S.u.S.E)