VYPR

munge

by OpenSUSE

CVEs (2)

  • CVE-2026-25506HigFeb 10, 2026
    risk 0.50cvss 7.7epss 0.00

    MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key…

  • CVE-2019-3691HigJan 23, 2020
    risk 0.50cvss 7.7epss 0.01

    A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects: SUSE Linux Enterprise Server 15 munge versions prior to…