SUSE has issued an update for multiple packages. This fixes a weakness, security issues, and vulnerabilities, where some have unknown impacts and others can be exploited by malicious people with physical access to bypass certain security restrictions and by malicious people to bypass certain security restrictions, disclose system information, manipulate certain data, disclose potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
1) The "mount.cifs" utility does not properly sanitise certain input, which can be exploited to corrupt the /etc/mtab file.
Successful exploitation requires that "mount.cifs" is setuid root (not setuid root by default).
Solution Apply updated packages via YaST Online Update or the SUSE FTP server. Original Advisory SUSE-SR:2010:008:
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new
versions, exploits, faulty patches, links, and other relevant data by
posting comments to this Advisory. You can also send this information to
vuln@secunia.com
Subject: SUSE Update for Multiple Packages
No posts yet
You must be logged in to post a comment.
Secunia Customer Login
Not a customer already?
Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance.