openSUSE和SUSE Linux Enterprise Server都是德国SUSE公司的产品。openSUSE是一套基于Linux的自由操作系统与开源社区项目。SUSE Linux Enterprise Server是一套企业服务器版Linux操作系统。 多款SUSE产品中的syslog-ng存在安全漏洞。本地攻击者可利用该漏洞提升权限。以下产品及版本受到影响:SUSE Linux Enterprise Debuginfo 11-SP3版本(syslog-ng 2.0.9-27.34.40.5.1
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SUSE | SUSE Linux Enterprise Debuginfo 11-SP3 | syslog-ng ~ 2.0.9-27.34.40.5.1 | - |
|
| SUSE | SUSE Linux Enterprise Debuginfo 11-SP4 | syslog-ng ~ 2.0.9-27.34.40.5.1 | - |
|
| SUSE | SUSE Linux Enterprise Module for Legacy Software 12 | syslog-ng ~ 3.6.4-12.8.1 | - |
|
| SUSE | SUSE Linux Enterprise Point of Sale 11-SP3 | syslog-ng ~ 2.0.9-27.34.40.5.1 | - |
|
| SUSE | SUSE Linux Enterprise Server 11-SP4-LTSS | syslog-ng ~ 2.0.9-27.34.40.5.1 | - |
|
| SUSE | SUSE Linux Enterprise Server for SAP 12-SP1 | syslog-ng ~ 3.6.4-12.8.1 | - |
|
| openSUSE | openSUSE Backports SLE-15-SP1 | syslog-ng ~ 3.19.1-bp151.4.6.1 | - |
|
| openSUSE | openSUSE Leap 15.1 | syslog-ng ~ 3.19.1-lp151.3.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-8022 | 7.7 HIGH | User-writeable configuration file /usr/lib/tmpfiles.d/tomcat.conf allows for escalation of |
| CVE-2019-3681 | 7.5 HIGH | osc: stores downloaded (supposed) RPM in network-controlled filesystem paths |
No comments yet