suse · CVE-2014-8169

Quick triage

Priority: medium Published: 2021-05-30 13:23:56 UTC Updated: 2026-04-18 18:33:27 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2014-8169 severity moderate: SUSE including 247 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 261 product×package rows across 31 product lines (SUSE Liberty Linux 7, SUSE Linux Enterprise Desktop 12, … (31 product lines)): Known Affected 231, Fixed 30.

Description:

automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environment variable values instead of the values for the user used to run the mapped program, which allows local users to gain privileges via a Trojan horse program in the user home directory.

cvelogic Threat Intelligence