Link following in systemd and Opensuse - CVE-2012-0871
Published: April 18, 2014 / Updated: August 10, 2020
SUSE
systemd
Opensuse
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.
The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.