UNIX symbolic link following in pesign - CVE-2022-3560
Published: February 26, 2023
Vulnerability identifier: #VU72572
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3560
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to read privileges files on the system.
The vulnerability exists due to a symlink following issue. A local user can create a specially crafted symbolic link to a critical file on the system and view it.
Affected software
pesign
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
CentOS
Anolis OS
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
openEuler
Fedora
pesign
pesign (Red Hat package)
pesign-debugsource
pesign-debuginfo
pesign-help
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
CentOS
Anolis OS
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
openEuler
Fedora
pesign
pesign (Red Hat package)
pesign-debugsource
pesign-debuginfo
pesign-help
How to mitigate CVE-2022-3560
Install updates from vendor's website.
pesign - update to 116
pesign - addressed in versions 0.109-11, 0.112-27.0.1
pesign (Red Hat package) - addressed in versions 0.109-11.el7_9, 0.112-25.el8_1.1, 0.112-25.el8_2.1, 0.112-25.el8_4.1, 0.112-27.el8_6, 0.112-27.el8_7, 115-6.el9_0, 115-6.el9_1
pesign - update to 0.112-150000.4.15.1
pesign-debugsource - update to 0.112-150000.4.15.1
pesign-debuginfo - update to 0.112-150000.4.15.1
pesign - addressed in versions 0.113-5, 115-4
pesign-debuginfo - addressed in versions 0.113-5, 115-4
pesign-help - addressed in versions 0.113-5, 115-4
pesign-debugsource - addressed in versions 0.113-5, 115-4
pesign - addressed in versions 115-4.fc36, 116-1.fc37
pesign - update to 116-2
pesign - addressed in versions 0.109-11, 0.112-27.0.1
pesign (Red Hat package) - addressed in versions 0.109-11.el7_9, 0.112-25.el8_1.1, 0.112-25.el8_2.1, 0.112-25.el8_4.1, 0.112-27.el8_6, 0.112-27.el8_7, 115-6.el9_0, 115-6.el9_1
pesign - update to 0.112-150000.4.15.1
pesign-debugsource - update to 0.112-150000.4.15.1
pesign-debuginfo - update to 0.112-150000.4.15.1
pesign - addressed in versions 0.113-5, 115-4
pesign-debuginfo - addressed in versions 0.113-5, 115-4
pesign-help - addressed in versions 0.113-5, 115-4
pesign-debugsource - addressed in versions 0.113-5, 115-4
pesign - addressed in versions 115-4.fc36, 116-1.fc37
pesign - update to 116-2
External References
Related Security Bulletins
- Information disclosure in pesign
- SUSE update for pesign
- Red Hat Enterprise Linux 9 update for pesign
- Red Hat Enterprise Linux 8.4 Extended Update Support update for pesign
- Red Hat Enterprise Linux 9.0 Extended Update Support update for pesign
- Red Hat Enterprise Linux 7 update for pesign
- Red Hat Enterprise Linux 8 update for pesign
- CentOS 7 update for pesign
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for pesign
- Red Hat Enterprise Linux 8 update for pesign
- Red Hat Enterprise Linux 8.6 Extended Update Support update for pesign
- Multiple vulnerabilities in Oracle Linux
- Fedora 36 update for pesign
- Fedora 37 update for pesign
- openEuler update for pesign
- openEuler 22.03 LTS SP1 update for pesign
- Amazon Linux AMI update for pesign
- Anolis OS update for pesign
- Anolis OS update for pesign