Security Advisory
CVE-2011-1551
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow local users to gain privileges by leveraging access to this account during root filesystem operations by the Cobbler daemon.