SUSE Linux Enterprise Server是德国SUSE公司的一套企业服务器版Linux操作系统。 SUSE Linux Enterprise Server中的permissions存在后置链接漏洞。该漏洞源于网络系统或产品未正确过滤表示非预期资源的链接或者快捷方式的文件名。攻击者可利用该漏洞访问非法的文件路径。以下产品及版本受到影响:SUSE Linux Enterprise Server 12版本(permissions 2015.09.28.1626-17.27.1之前版本),SUSE
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SUSE | SUSE Linux Enterprise Server 12 | permissions ~ 2015.09.28.1626-17.27.1 | - |
|
| SUSE | SUSE Linux Enterprise Server 15 | permissions ~ 20181116-9.23.1 | - |
|
| SUSE | SUSE Linux Enterprise Server 11 | permissions ~ 2013.1.7-0.6.12.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-18897 | 8.4 HIGH | Local privilege escalation from user salt to root |
| CVE-2019-18902 | 7.5 HIGH | wicked: Use-after-free when receiving invalid DHCP6 client options |
| CVE-2019-18903 | 7.5 HIGH | wicked: Use-after-free when receiving invalid DHCP6 IA_PD option |
| CVE-2019-18901 | 5.1 MEDIUM | mysql-systemd-helper allows setting 640 permissions of arbitrary files |
No comments yet