7.8

CVE-2016-5759

The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Novell ≫ Suse Linux Enterprise Desktop Version 12.0 Update sp1
Novell ≫ Suse Linux Enterprise Server Version 12.0 Update sp1
Opensuse ≫ Leap Version 42.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.298
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.opensuse.org/opensuse-updates/2016-10/msg00083.html
http://lists.suse.com/pipermail/sle-security-updates/2016-October/002337.html