CVE-2009-1297: Medium severity suse linux vulnerability
iscsidiscovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1297?
CVE-2009-1297 is considered a medium severity vulnerability due to its potential for local file overwriting.
How do I fix CVE-2009-1297?
To fix CVE-2009-1297, update to the latest version of open-iscsi that addresses this symlink vulnerability.
Who is affected by CVE-2009-1297?
CVE-2009-1297 affects local users on SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise 10 SP2 and 11.
What type of attack is CVE-2009-1297 associated with?
CVE-2009-1297 is associated with a symlink attack that allows the overwriting of arbitrary files.
Is remote exploitation possible with CVE-2009-1297?
No, CVE-2009-1297 requires local user access, making it a local privilege escalation vulnerability.