The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to 081d081dcfaf61710bda34bc21c80c66276119aa.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://bugzilla.suse.com/show_bug.cgi?id=1148788 | issue tracking vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00010.html | vendor advisory |