YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Suse_linux | Suse | 8.2 (including) | 8.2 (including) |
Suse_linux | Suse | 9.0 (including) | 9.0 (including) |