CVE-2009-1297
Last modified
CVE-2009-1297 is a vulnerability of currently unknown severity. iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Novell | Suse Linux | 10 | Sp2 |
| Novell | Suse Linux | 11 | — |
| Opensuse | Opensuse | 10.3 | — |
| Opensuse | Opensuse | 11.1 | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1297?
How severe is CVE-2009-1297?
How do I fix CVE-2009-1297?
Are you affected by CVE-2009-1297?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
