CVE-2011-1551

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
30/03/2011
Last modified:
11/04/2025

Description

SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow local users to gain privileges by leveraging access to this account during root filesystem operations by the Cobbler daemon.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:novell:opensuse_factory:*:*:*:*:*:*:*:*