A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versions prior to 2.06-150400.7.1. SUSE openSUSE Factory grub2 versions prior to 2.06-18.1.
CVSS Details
- CVSS 3.1 Base Score: 5.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade grub2-snapper-pluginUpgrade grub2-i386-pcUpgrade grub2-systemd-sleep-pluginUpgrade grub2-s390x-emuUpgrade grub2Upgrade grub2-powerpc-ieee1275Upgrade grub2-x86_64-xenUpgrade grub2-arm64-efiUpgrade grub2-x86_64-efi | Oct 26, 2022 | Mar 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub