|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2005-3148: storebackup symlink attack | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Marcus Meissner <meissner> |
| Component: | Incidents | Assignee: | Matthias Eckermann <mge> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | mge, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | CVE-2005-3148: CVSS v2 Base Score: 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P) | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Marcus Meissner
2005-02-02 20:29:02 UTC
<!-- SBZ_reproduce --> see above I have contacted the mainstream author, ... so short MgE It's too late for a workaround for 9.3 I think, right? Matthias is unable to access this bug. Looks like the bugzilla setup isn't flawless yet. We may get results regarding this bug on friday. matthias, please mail me offline what exact bugzilla address you use. you can only read this bug as mge@suse.de currently, but you probably use your novell account. matthias fixed this for STABLE, which is good enough. CAN-2005-3148 CVE-2005-3148: CVSS v2 Base Score: 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P) |