CVE-2022-31253: openldap2: /usr/lib/openldap/start allows ldap user/group to recursively chown arbitrary directory trees to itself
Published Nov 9, 2022
·Updated
A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root. This issue affects: openSUSE Factory openldap2 versions prior to 2.6.3-404.1.
Affected Software
1 affected component
OpenSUSE openldap2<2.6.3-404.1
Event History
Nov 9, 2022
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-31253.
2
What is the severity of CVE-2022-31253?
The severity of CVE-2022-31253 is high with a severity value of 7.8.
3
What is the affected software?
The affected software is openldap2 of openSUSE Factory.
4
How does CVE-2022-31253 affect openldap2 of openSUSE Factory?
CVE-2022-31253 allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root.
5
How can I fix CVE-2022-31253?
To fix CVE-2022-31253, update openldap2 to version 2.6.3-404.1 or later.