CVE-2012-0420
02.12.2013, 04:36
zypp-refresh-wrapper in SUSE Zypper before 1.3.20 and 1.6.x before 1.6.166 allows local users to create files in arbitrary directories, or possibly have unspecified other impact, via a pathname in the ZYPP_LOCKFILE_ROOT environment variable.Enginsight
Vendor | Product | Version |
---|---|---|
opensuse | zypper | 𝑥 ≤ 1.2.8 |
opensuse | zypper | 0.11.6 |
opensuse | zypper | 1.0.2 |
opensuse | zypper | 1.6.16 |
𝑥
= Vulnerable software versions