SB2014020606 - Link following in Novell Opensuse
Published: February 6, 2014 Updated: August 10, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Link following (CVE-ID: CVE-2010-4226)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.
Remediation
Install update from vendor's website.