The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances involving reboots during online updates, which makes it easier for remote attackers to access network services.
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:PSUSE Linux
OSSuse11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Firewall
CWE
Related vulnerabilities
CVE-2002-0083CRITICAL9.8PL ✓same product
OpenSSH: błąd off-by-one w kodzie kanałów umożliwia eskalację uprawnień
CVE-1999-0426CRITICAL9.8PL ✓same product
Nieprawidłowe uprawnienia /dev/kmem umożliwiają IP spoofing w Linux
CVE-2024-12085HIGH7.5same product
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an att...
CVE-2017-3224HIGH8.2same product
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LS...
CVE-2010-0230HIGH7.5same product
SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfa...