First published: Fri Oct 23 2009(Updated: )
iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =10-sp2 | |
SUSE Linux | =11 | |
openSUSE | =10.3 | |
openSUSE | =11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1297 is considered a medium severity vulnerability due to its potential for local file overwriting.
To fix CVE-2009-1297, update to the latest version of open-iscsi that addresses this symlink vulnerability.
CVE-2009-1297 affects local users on SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise 10 SP2 and 11.
CVE-2009-1297 is associated with a symlink attack that allows the overwriting of arbitrary files.
No, CVE-2009-1297 requires local user access, making it a local privilege escalation vulnerability.