Vulnerabilities > CVE-2017-9286 - Unspecified vulnerability in Opensuse Leap 42.3
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 |
Nessus
NASL family | SuSE Local Security Checks |
NASL id | OPENSUSE-2017-1121.NASL |
description | This update for nextcloud fixes the following issues : - CVE-2017-9286: During upgrade of the nextcloud package local attackers could gain root access via a /tmp file race. (boo#1036756) |
last seen | 2020-06-05 |
modified | 2017-10-04 |
plugin id | 103661 |
published | 2017-10-04 |
reporter | This script is Copyright (C) 2017-2020 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/103661 |
title | openSUSE Security Update : nextcloud (openSUSE-2017-1121) |
code |
|
References
- https://bugzilla.suse.com/show_bug.cgi?id=1036756
- https://bugzilla.suse.com/show_bug.cgi?id=1036756
- https://lists.opensuse.org/opensuse-updates/2017-10/msg00010.html
- https://lists.opensuse.org/opensuse-updates/2017-10/msg00010.html
- https://www.suse.com/de-de/security/cve/CVE-2017-9286/
- https://www.suse.com/de-de/security/cve/CVE-2017-9286/