First published: Tue Jun 02 2015(Updated: )
GNU Parallel before 20150522 (Nepal), when using (1) --cat or (2) --fifo with --sshlogin, allows local users to write to arbitrary files via a symlink attack on a temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =13.1 | |
SUSE Linux | =13.2 | |
GNU Parallel | <=20150322 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4156 is considered a moderate severity vulnerability due to its potential for local privilege escalation via symlink attacks.
To fix CVE-2015-4156, update GNU Parallel to version 20150522 or later.
CVE-2015-4156 affects users of GNU Parallel prior to version 20150522 running on specific versions of openSUSE.
CVE-2015-4156 allows local users to overwrite arbitrary files, potentially compromising system integrity.
CVE-2015-4156 is not exploitable remotely as it requires local access to the system.