CVE-2015-0794: Low severity dracut vulnerability
Published Nov 19, 2015
·Updated
modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracutblockuuid.map.
Affected Software
2 affected components
Dracut Project Dracut<037-17.30.1
openSUSE openSUSE=13.2
Event History
Nov 19, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0794?
CVE-2015-0794 has a moderate severity rating due to its potential for local user exploitation through a symlink attack.
2
How do I fix CVE-2015-0794?
To fix CVE-2015-0794, update the dracut package to version 037-17.30.1 or later.
3
What does CVE-2015-0794 affect?
CVE-2015-0794 affects the dracut package in openSUSE 13.2 prior to version 037-17.30.1.
4
Can CVE-2015-0794 be exploited by remote attackers?
CVE-2015-0794 is not exploitable by remote attackers as it requires local access to the system.
5
What is a symlink attack in the context of CVE-2015-0794?
A symlink attack in CVE-2015-0794 involves creating a symbolic link to manipulate file access, potentially leading to unauthorized actions.