UNIX symbolic link following in sendmail - CVE-2022-31256
Published: November 14, 2022
Vulnerability identifier: #VU69301
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31256
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a symlink following issue in a script called by the sendmail systemd service. A local user can create a specially crafted symbolic link to a critical file on the system and escalate privileges from mail to root.
Affected software
sendmail
SUSE Linux Enterprise Module for Packagehub Subpackages
sendmail-debuginfo
sendmail-debugsource
libmilter1_0
libmilter1_0-debuginfo
rmail
rmail-debuginfo
sendmail-devel
libmilter-doc
sendmail-starttls
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
SUSE Linux Enterprise Module for Packagehub Subpackages
sendmail-debuginfo
sendmail-debugsource
libmilter1_0
libmilter1_0-debuginfo
rmail
rmail-debuginfo
sendmail-devel
libmilter-doc
sendmail-starttls
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
How to mitigate CVE-2022-31256
Install updates from vendor's website.
sendmail - addressed in versions 8.14.9-4.6.1, 8.15.2-150000.8.9.1
sendmail-debuginfo - addressed in versions 8.14.9-4.6.1, 8.15.2-150000.8.9.1
sendmail-debugsource - addressed in versions 8.14.9-4.6.1, 8.15.2-150000.8.9.1
libmilter1_0 - update to 8.15.2-150000.8.9.1
libmilter1_0-debuginfo - update to 8.15.2-150000.8.9.1
rmail - update to 8.15.2-150000.8.9.1
rmail-debuginfo - update to 8.15.2-150000.8.9.1
sendmail-devel - update to 8.15.2-150000.8.9.1
libmilter-doc - update to 8.15.2-150000.8.9.1
sendmail-starttls - update to 8.15.2-150000.8.9.1
sendmail-debuginfo - addressed in versions 8.14.9-4.6.1, 8.15.2-150000.8.9.1
sendmail-debugsource - addressed in versions 8.14.9-4.6.1, 8.15.2-150000.8.9.1
libmilter1_0 - update to 8.15.2-150000.8.9.1
libmilter1_0-debuginfo - update to 8.15.2-150000.8.9.1
rmail - update to 8.15.2-150000.8.9.1
rmail-debuginfo - update to 8.15.2-150000.8.9.1
sendmail-devel - update to 8.15.2-150000.8.9.1
libmilter-doc - update to 8.15.2-150000.8.9.1
sendmail-starttls - update to 8.15.2-150000.8.9.1