modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_uuid.map.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0794
Reference (s):
- MLIST:[opensuse-bugs] 20150619 [Bug 935338] VUL-0: CVE-2015-0794: dracut: uses hardcoded /tmp/dracut_block_uuid.map filename – symlink attack
- URL: http://lists.opensuse.org/opensuse-bugs/2015-06/msg02585.html
- MLIST:[opensuse-bugs] 20150619 [Bug 935338] dracut uses hardcoded /tmp/dracut_block_uuid.map filename – symlink attack
- URL: http://lists.opensuse.org/opensuse-bugs/2015-06/msg02580.html
- SUSE:openSUSE-SU-2015:2022

