UNIX symbolic link following in clone-master-clean-up - CVE-2021-32000

 

UNIX symbolic link following in clone-master-clean-up - CVE-2021-32000

Published: October 20, 2022


Vulnerability identifier: #VU68560
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32000
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a symlink following issue in the clone-master-clean-up.sh script of clone-master-clean-up. A local user can create a specially crafted symbolic link to a critical file on the system and delete it, causing a denial of service.


Affected software

clone-master-clean-up
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise High Performance Computing
openSUSE Leap

How to mitigate CVE-2021-32000

Install updates from vendor's website.

clone-master-clean-up - addressed in versions 1.8-150100.3.14.1, 1.8-4.11.1

External References

Related Security Bulletins