First published: Wed Nov 09 2022(Updated: )
A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root. This issue affects: openSUSE Factory openldap2 versions prior to 2.6.3-404.1.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Opensuse Openldap2 | <2.6.3-404.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-31253.
The severity of CVE-2022-31253 is high with a severity value of 7.8.
The affected software is openldap2 of openSUSE Factory.
CVE-2022-31253 allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root.
To fix CVE-2022-31253, update openldap2 to version 2.6.3-404.1 or later.