CVE-2015-4156: Low severity suse linux vulnerability
Published Jun 2, 2015
·Updated
GNU Parallel before 20150522 (Nepal), when using (1) --cat or (2) --fifo with --sshlogin, allows local users to write to arbitrary files via a symlink attack on a temporary file.
Affected Software
3 affected components
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
GNU Parallel<=20150322
Event History
Jun 2, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4156?
CVE-2015-4156 is considered a moderate severity vulnerability due to its potential for local privilege escalation via symlink attacks.
2
How do I fix CVE-2015-4156?
To fix CVE-2015-4156, update GNU Parallel to version 20150522 or later.
3
Who is affected by CVE-2015-4156?
CVE-2015-4156 affects users of GNU Parallel prior to version 20150522 running on specific versions of openSUSE.
4
What impact does CVE-2015-4156 have on security?
CVE-2015-4156 allows local users to overwrite arbitrary files, potentially compromising system integrity.
5
Is CVE-2015-4156 exploitable remotely?
CVE-2015-4156 is not exploitable remotely as it requires local access to the system.