CVE-2021-36781: parsec: dangerous 777 permissions for /run/parsec
Published Jan 14, 2022
·Updated
A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1.
Affected Software
1 affected component
openSUSE Factory<0.8.1-1.1
Remediation
Patch Available
Event History
Jan 14, 2022
CVE Published
via MITRE·10:40 AM
Data Sourced
via MITRE·10:40 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-36781.
2
What is the title of this vulnerability?
The title of this vulnerability is 'A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service'.
3
What is the severity level of CVE-2021-36781?
The severity level of CVE-2021-36781 is medium.
4
How does CVE-2021-36781 affect openSUSE Factory parsec?
CVE-2021-36781 affects openSUSE Factory parsec versions prior to 0.8.1-1.1.
5
Is there a fix available for CVE-2021-36781?
Yes, the fix for CVE-2021-36781 is available in parsec version 0.8.1-1.1.