Executive brief
A vulnerability exists in the Pardus About component of the Pardus operating system, which provides system information to users. An attacker can use a specially crafted link to trick the system into accessing or modifying files it shouldn't, potentially leading to a full system compromise or data loss. This issue is resolved in version 1.2.2 of the software.
Technical details
The Pardus About component suffers from an improper link resolution (CWE-59) vulnerability, commonly known as a symlink attack. The software fails to properly validate file paths before access, allowing an attacker to create symbolic links that point to sensitive system files. While the attack vector is listed as network-based, it requires user interaction (UI:R) to succeed. If exploited, an attacker can achieve high impact across confidentiality, integrity, and availability. The vulnerability is addressed in version 1.2.2.
Affected products
- TUBITAK BILGEM Software Technologies Research Institute Pardus About before 1.2.2
Timeline
- 2026-04-29: disclosed
- 2026-04-29: advisory