Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

openSUSE 12.1: SUSE-SA:2012:001 Critical: Local Escalation via Systemd

suse
Calendar Grey February 29, 2012
Dist Suse Esm H88
Urgent SUSE notice regarding systemd software aimed at preventing local privilege elevation. Apply updates to defend against symlink vulnerabilities.
systemd-logind, part of the systemd package, keeps track of user systemd-logind, part of the systemd package, keeps track of user logins and sessions

Summary

References

Cross- CVE-2012-0871

Content of This Advisory:

1) Security Vulnerability Resolved:

systemd arbitrary file creation

Problem Description

2) Solution or Work-Around

3) Special Instructions and Notes

4) Package Location and Checksums

5) Pending Vulnerabilities, Solutions, and Work-Arounds:

none.

6) Authenticity Verification and Additional Information

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SA:2012:001
Date: Wed, 29 Feb 2012 16:00:00 +0000
Affected Products: openSUSE 12.1
Vulnerability Type: local privilege escalation
CVSS v2 Base Score: 6.6 (AV:L/AC:M/Au:S/C:C/I:C/A:C)
SUSE Default Package: yes

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here