7.8
CVE-2020-8023
- EPSS 0.41%
- Veröffentlicht 01.09.2020 12:15:10
- Zuletzt bearbeitet 21.11.2024 05:38:14
- Erkennungen
Local privilege escalation from ldap to root when using OPENLDAP_CONFIG_BACKEND=ldap in openldap2
A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SECURITY, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 12-SP2, SUSE Linux Enterprise Server for SAP 12-SP3, SUSE Linux Enterprise Server for SAP 15, SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud Crowbar 8; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to escalate privileges from user ldap to root. This issue affects: SUSE Enterprise Storage 5 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Debuginfo 11-SP3 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Debuginfo 11-SP4 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Point of Sale 11-SP3 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Server 11-SECURITY openldap2-client-openssl1 versions prior to 2.4.26-0.74.13.1. SUSE Linux Enterprise Server 11-SP4-LTSS openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Server 12-SP2-BCL openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP2-LTSS openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP3-BCL openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP3-LTSS openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP4 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP5 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.31.1. SUSE Linux Enterprise Server for SAP 12-SP2 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server for SAP 12-SP3 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server for SAP 15 openldap2 versions prior to 2.4.46-9.31.1. SUSE OpenStack Cloud 7 openldap2 versions prior to 2.4.41-18.71.2. SUSE OpenStack Cloud 8 openldap2 versions prior to 2.4.41-18.71.2. SUSE OpenStack Cloud Crowbar 8 openldap2 versions prior to 2.4.41-18.71.2. openSUSE Leap 15.1 openldap2 versions prior to 2.4.46-lp151.10.12.1. openSUSE Leap 15.2 openldap2 versions prior to 2.4.46-lp152.14.3.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opensuse ≫ Openldap2 Version < 2.4.41-18.71.2
Suse ≫ Enterprise Storage Version 5.0
Suse ≫ Openstack Cloud Version 7.0
Suse ≫ Openstack Cloud Version 8.0
Suse ≫ Openstack Cloud Crowbar Version 8.0
Suse ≫ Linux Enterprise Server Version 12 Update sp2
Suse ≫ Linux Enterprise Server Version 12 Update sp2 SwPlatform sap
Suse ≫ Linux Enterprise Server Version 12 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 12 Update sp3 SwPlatform sap
Suse ≫ Linux Enterprise Server Version 12 Update sp3 SwEdition - SwPlatform -
Suse ≫ Linux Enterprise Server Version 12 Update sp3 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 12 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update sp5
Suse ≫ Openstack Cloud Version 7.0
Suse ≫ Openstack Cloud Version 8.0
Suse ≫ Openstack Cloud Crowbar Version 8.0
Suse ≫ Linux Enterprise Server Version 12 Update sp2
Suse ≫ Linux Enterprise Server Version 12 Update sp2 SwPlatform sap
Suse ≫ Linux Enterprise Server Version 12 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 12 Update sp3 SwPlatform sap
Suse ≫ Linux Enterprise Server Version 12 Update sp3 SwEdition - SwPlatform -
Suse ≫ Linux Enterprise Server Version 12 Update sp3 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 12 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update sp5
Opensuse ≫ Openldap2 Version < 2.4.26-0.74.13.1
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp3
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp4
Suse ≫ Linux Enterprise Point Of Sale Version 11 Update sp3
Suse ≫ Linux Enterprise Server Version 11 Update -
Suse ≫ Linux Enterprise Server Version 11 Update sp4 SwEdition ltss
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp4
Suse ≫ Linux Enterprise Point Of Sale Version 11 Update sp3
Suse ≫ Linux Enterprise Server Version 11 Update -
Suse ≫ Linux Enterprise Server Version 11 Update sp4 SwEdition ltss
Opensuse ≫ Openldap2 Version < 2.4.46-9.31.1
Suse ≫ Linux Enterprise Server Version 15 SwPlatform ltss
Suse ≫ Linux Enterprise Server Version 15 SwPlatform sap
Suse ≫ Linux Enterprise Server Version 15 SwPlatform sap
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.323 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
| SUSE | 7.7 | 2.5 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-349 Acceptance of Extraneous Untrusted Data With Trusted Data
The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.
https://bugzilla.suse.com/show_bug.cgi?id=1172698