7.8

CVE-2020-8026

inn: non-root owned files

A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version 2.6.2-lp152.1.26 and prior versions. openSUSE Tumbleweed inn version 2.6.2-4.2 and prior versions. openSUSE Leap 15.1 inn version 2.5.4-lp151.3.3.1 and prior versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opensuse ≫ Backports Sle Version 15.0 Update sp1
Opensuse ≫ Backports Sle Version 15.0 Update sp2
Opensuse ≫ Tumbleweed Version <= 2.6.2-4.2
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 15.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.279
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
SUSE 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00063.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00064.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00074.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00038.html
Third Party Advisory
Mailing List
https://bugzilla.suse.com/show_bug.cgi?id=1172573
Vendor Advisory
Issue Tracking