← Back

CVE-2020-8013

nvd nist
Published: Mar 2, 2020Modified: Nov 21, 2024

JSON object

Loading...
2.5
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 1.0 / Impact: 1.4
Source: NVD

Description

A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 11 set permissions intended for specific binaries on other binaries because it erroneously followed symlinks. The symlinks can't be controlled by attackers on default systems, so exploitation is difficult. This issue affects: SUSE Linux Enterprise Server 12 permissions versions prior to 2015.09.28.1626-17.27.1. SUSE Linux Enterprise Server 15 permissions versions prior to 20181116-9.23.1. SUSE Linux Enterprise Server 11 permissions versions prior to 2013.1.7-0.6.12.1.

Affected (4)

1 product
Linux Enterprise Server
1 product
Leap
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Suse
Version 11
Version 12
Version 15
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1

References (4)

Source: meissner@suse.de
Mailing ListVendor Advisory
Source: meissner@suse.de
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.