UNIX symbolic link following in clone-master-clean-up - CVE-2021-32000
Published: October 20, 2022
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a symlink following issue in the clone-master-clean-up.sh script of clone-master-clean-up. A local user can create a specially crafted symbolic link to a critical file on the system and delete it, causing a denial of service.
Affected software
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise High Performance Computing
openSUSE Leap