Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-12218 | A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Factory, Leap 15.2 allows local attackers with control of the runtime user to run arpwatch as to escalate to root upon the next restart of arpwatch. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS arpwatch versions prior to 2.1a15. SUSE Manager Server 4.0 arpwatch versions prior to 2.1a15. SUSE OpenStack Cloud Crowbar 9 arpwatch versions prior to 2.1a15. openSUSE Factory arpwatch version 2.1a15-169.5 and prior versions. openSUSE Leap 15.2 arpwatch version 2.1a15-lp152.5.5 and prior versions. |
No history.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2024-09-16T18:43:24.802Z
Reserved: 2021-01-19T00:00:00.000Z
Link: CVE-2021-25321
No data.
Status : Modified
Published: 2021-06-30T09:15:08.150
Modified: 2026-06-17T03:41:49.507
Link: CVE-2021-25321
OpenCVE Enrichment
No data.
-
CWE-61
UNIX Symbolic Link (Symlink) Following
-
CWE-732
Incorrect Permission Assignment for Critical Resource
- NVD-CWE-Other
EUVD