First published: Fri Apr 01 2011(Updated: )
/etc/init.d/boot.localfs in the aaa_base package before 11.2-43.48.1 in SUSE openSUSE 11.2, and before 11.3-8.7.1 in openSUSE 11.3, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/mtab.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE | =11.2 | |
openSUSE | =11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0461 is considered to be of medium severity due to its potential for local users to exploit a symlink vulnerability.
To fix CVE-2011-0461, update the aaa_base package to version 11.2-43.48.1 or later for openSUSE 11.2 or to version 11.3-8.7.1 or later for openSUSE 11.3.
CVE-2011-0461 affects local users on openSUSE 11.2 and 11.3 who have access to modify files via symlink attacks.
CVE-2011-0461 impacts openSUSE versions 11.2 before 11.2-43.48.1 and 11.3 before 11.3-8.7.1.
CVE-2011-0461 is associated with a symlink attack that allows local users to overwrite arbitrary files.