CVE-2015-4156: GNU Parallel

Low severity, CVSS 3.6. EPSS: 0.4% chance of exploitation in the next 30 days.

GNU Parallel before 20150522 (Nepal), when using (1) --cat or (2) --fifo with --sshlogin, allows local users to write to arbitrary files via a symlink attack on a temporary file.

Affected products

  • GNU Parallel: up to and including 20150322
  • Opensuse Opensuse: version 13.1 only; version 13.2 only

Published 2015-06-02. Last modified 2026-06-17.