LWN.net Logo

cobbler: privilege escalation

Package(s):cobbler CVE #(s):CVE-2011-1551
Created:April 1, 2011 Updated:April 6, 2011
Description: From the openSUSE advisory:

/var/log/cobbler/ directory was owned by the web service user. Access to this account could potentially be abused to corrupt files during root filesystem operations by the Cobbler daemon.

Alerts:
SUSE SUSE-SR:2011:006 2011-04-05
openSUSE openSUSE-SU-2011:0277-1 2011-04-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds