CVE-2008-4636

yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell Linux allows local users to gain privileges via shell metacharacters in filenames used by the backup process.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:novell:suse_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux:10.1:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux:10:*:desktop:*:*:*:*:*
cpe:2.3:o:novell:suse_linux:10:*:server:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:10.2:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_server:9:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:10.3:*:*:*:*:*:*:*
cpe:2.3:o:novell:opensuse:*:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux:*:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:*:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux:9.3:*:pro:*:*:*:*:*
cpe:2.3:o:novell:suse_linux:9:*:server:*:*:*:*:*
OR cpe:2.3:o:suse:yast2-backup:2.14.2:*:*:*:*:*:*:*
cpe:2.3:o:suse:yast2-backup:*:*:*:*:*:*:*:*

Information

Published : 2008-11-27 00:30

Updated : 2018-10-30 16:27


NVD link : CVE-2008-4636

Mitre link : CVE-2008-4636


JSON object : View

Products Affected

novell

  • suse_linux
  • suse_linux_enterprise_server
  • opensuse

opensuse

  • opensuse

suse

  • yast2-backup
CWE
CWE-20

Improper Input Validation