liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exploit CVE-2005-3013.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Suse_linux_openexchange_server | Suse | 4.0 (including) | 4.0 (including) |
Suse_linux_school_server | Suse | gold (including) | gold (including) |
Suse_linux_standard_server | Suse | 8.0 (including) | 8.0 (including) |
Suse_sled_beagle | Suse | 10.0 (including) | 10.0 (including) |