The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances involving reboots during online updates, which makes it easier for remote attackers to access network services.
oryginał ENCVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:PSUSE Linux
OSSuse11
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Firewall
CWE
Powiązane podatności
CVE-2002-0083CRITICAL9.8PL ✓ten sam produkt
OpenSSH: błąd off-by-one w kodzie kanałów umożliwia eskalację uprawnień
CVE-1999-0426CRITICAL9.8PL ✓ten sam produkt
Nieprawidłowe uprawnienia /dev/kmem umożliwiają IP spoofing w Linux
CVE-2024-12085HIGH7.5ten sam produkt
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an att...
CVE-2017-3224HIGH8.2ten sam produkt
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LS...
CVE-2010-0230HIGH7.5ten sam produkt
SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfa...