Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2011-0461

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Novell openSUSE是美国Novell公司的一套基于Linux的自由操作系统。 openSUSE的aaa_base包中的/etc/init.d/boot.localfs中存在后置链接漏洞。本地用户可以借助/dev/shm/mtab中的符号链接攻击,覆盖任意文件。

AI Predicted 3.3 Difficulty: Easy EPSS 0.30% · P22
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2011-0461

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
/etc/init.d/boot.localfs in the aaa_base package before 11.2-43.48.1 in SUSE openSUSE 11.2, and before 11.3-8.7.1 in openSUSE 11.3, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/mtab.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Novell openSUSE aaa_base包/etc/init.d/boot.localfs任意文件覆盖漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Novell openSUSE是美国Novell公司的一套基于Linux的自由操作系统。 openSUSE的aaa_base包中的/etc/init.d/boot.localfs中存在后置链接漏洞。本地用户可以借助/dev/shm/mtab中的符号链接攻击,覆盖任意文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2011-0461

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-0461

登录查看更多情报信息。

Vendor Advisories for CVE-2011-0461 (1)

Mailing List Discussions for CVE-2011-0461 (2)

Other References for CVE-2011-0461 (1)

Same Patch Batch · n/a · 2011-04-01 · 13 CVEs total

CVE-2010-3447 Horde Gollem文件浏览器view.php跨站脚本攻击漏洞
CVE-2010-3693 Horde Dynamic IMP和Groupware Webmail跨站脚本攻击漏洞
CVE-2010-4235 RealNetworks Helix Server 'x-wap-profile'头选项格式串处理漏洞
CVE-2010-4596 RealNetworks Helix和Helix Mobile Server 'RTSP'栈缓冲区溢出漏洞
CVE-2010-4778 Horde IMP和Groupware Webmail多个跨站脚本攻击漏洞
CVE-2011-0468 Novell openSUSE 'aaa_base'标签扩展文件名处理权限提升漏洞
CVE-2011-0951 Cisco Secure Access Control System未授权密码更改安全策略绕过漏洞
CVE-2011-1126 VMware VIX API和Workstation 'vmrun'本地权限提升漏洞
CVE-2011-1546 Aphpkb Andy's PHP Knowledgebase多个SQL注入漏洞
CVE-2011-1555 Andy's PHP Knowledgebase saa.php SQL注入漏洞
CVE-2011-1556 Andy's PHP Knowledgebase 'pdfa' SQL注入漏洞
CVE-2011-1557 ICloudCenter ICJobSite SQL注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2011-0461

No comments yet


Leave a comment