← Back

CVE-2020-8023

nvd nist
Published: Sep 1, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SECURITY, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 12-SP2, SUSE Linux Enterprise Server for SAP 12-SP3, SUSE Linux Enterprise Server for SAP 15, SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud Crowbar 8; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to escalate privileges from user ldap to root. This issue affects: SUSE Enterprise Storage 5 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Debuginfo 11-SP3 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Debuginfo 11-SP4 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Point of Sale 11-SP3 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Server 11-SECURITY openldap2-client-openssl1 versions prior to 2.4.26-0.74.13.1. SUSE Linux Enterprise Server 11-SP4-LTSS openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Server 12-SP2-BCL openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP2-LTSS openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP3-BCL openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP3-LTSS openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP4 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP5 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.31.1. SUSE Linux Enterprise Server for SAP 12-SP2 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server for SAP 12-SP3 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server for SAP 15 openldap2 versions prior to 2.4.46-9.31.1. SUSE OpenStack Cloud 7 openldap2 versions prior to 2.4.41-18.71.2. SUSE OpenStack Cloud 8 openldap2 versions prior to 2.4.41-18.71.2. SUSE OpenStack Cloud Crowbar 8 openldap2 versions prior to 2.4.41-18.71.2. openSUSE Leap 15.1 openldap2 versions prior to 2.4.46-lp151.10.12.1. openSUSE Leap 15.2 openldap2 versions prior to 2.4.46-lp152.14.3.1.

Affected (4)

Products: Opensuse: Openldap2
1 product
Openldap2
Configuration A
1 vulnerable · 12 platform
Vulnerable SoftwareAffected Versions
Before 2.4.41-18.71.2
Running on/withPlatform Versions
Suse
Enterprise Storage
Version 5.0
Suse
Linux Enterprise Server
Version 12 sp2
Suse
Linux Enterprise Server
Version 12 sp2
Suse
Linux Enterprise Server
Version 12 sp2
Suse
Linux Enterprise Server
Version 12 sp3
Suse
Linux Enterprise Server
Version 12 sp3
Suse
Linux Enterprise Server
Version 12 sp3
Suse
Linux Enterprise Server
Version 12 sp4
Suse
Linux Enterprise Server
Version 12 sp5
Suse
Openstack Cloud
Version 7.0
Suse
Openstack Cloud
Version 8.0
Suse
Openstack Cloud Crowbar
Version 8.0
Configuration B
1 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Before 2.4.26-0.74.13.1
Running on/withPlatform Versions
Suse
Linux Enterprise Debuginfo
Version 11 sp3
Suse
Linux Enterprise Debuginfo
Version 11 sp4
Suse
Linux Enterprise Point Of Sale
Version 11 sp3
Suse
Linux Enterprise Server
Version 11
Suse
Linux Enterprise Server
Version 11 sp4
Configuration C
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 2.4.46-9.31.1
Running on/withPlatform Versions
Suse
Linux Enterprise Server
Version 15
Suse
Linux Enterprise Server
Version 15
Configuration D
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 2.4.46-lp151.10.12.1
Running on/withPlatform Versions
Opensuse
Leap
Version 15.1
Opensuse
Leap
Version 15.2

References (2)

Source: meissner@suse.de
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory

Timeline

No history available yet.