[Bug 1230552] VUL-0: CVE-2024-45770: pcp: `pmpost` symlink attack allows escalating `pcp` to `root` user
https://bugzilla.suse.com/show_bug.cgi?id=1230552 https://bugzilla.suse.com/show_bug.cgi?id=1230552#c13 --- Comment #13 from Maintenance Automation <maint-coord+maintenance-robot@suse.de> --- SUSE-SU-2024:3785-1: An update that solves three vulnerabilities, contains two features and has two security fixes can now be installed. URL: https://www.suse.com/support/update/announcement/2024/suse-su-20243785-1 Category: security (important) Bug References: 1217826, 1222815, 1230551, 1230552, 1231345 CVE References: CVE-2023-6917, CVE-2024-45769, CVE-2024-45770 Jira References: PED-8192, PED-8389 Maintenance Incident: [SUSE:Maintenance:35852](https://smelt.suse.de/incident/35852/) Sources used: openSUSE Leap 15.5 (src): pcp-6.2.0-150500.8.6.1 Development Tools Module 15-SP5 (src): pcp-6.2.0-150500.8.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com