Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10680 | A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This issue affects gerbera on openSUSE Tumbleweed before 2.5.0-1.1. |
| Link | Providers |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-23386 |
|
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Apr 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This issue affects gerbera on openSUSE Tumbleweed before 2.5.0-1.1. | |
| Title | gerbera: Privilege escalation from user gerbera to root because of insecure %post script | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2025-04-10T14:22:23.310Z
Reserved: 2025-01-15T12:39:03.323Z
Link: CVE-2025-23386
Updated: 2025-04-10T14:22:14.947Z
Status : Deferred
Published: 2025-04-10T10:15:14.697
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-23386
No data.
OpenCVE Enrichment
No data.
EUVD