Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-26880

Опубликовано: 07 окт. 2020
Источник: debian
EPSS Низкий

Описание

Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sympafixed6.2.60~dfsg-2package
sympapostponedbusterpackage
sympapostponedstretchpackage

Примечания

  • https://github.com/sympa-community/sympa/issues/1009

  • https://github.com/sympa-community/sympa/issues/943#issuecomment-704779420

  • https://github.com/sympa-community/sympa/issues/943#issuecomment-704842235

  • Mitigation: https://salsa.debian.org/sympa-team/sympa/-/commit/b904d5257beb135127f663ad8f6865c1b59efd50

  • Mitigation present in 6.2.58~dfsg-2, 6.2.40~dfsg-1+deb10u1 and 6.2.16~dfsg-3+deb9u4

  • uploads.

  • Upstream's take is that the issue is considered fixed with the combination of

  • https://github.com/sympa-community/sympa/issues/946

  • https://github.com/sympa-community/sympa/issues/1086

  • with both changes first included in 6.2.60~dfsg-2. From Debian point of view

  • consider this as sufficient coverage for the CVE-2020-26880 fix.

EPSS

Процентиль: 13%
0.00043
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 5 лет назад

Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.

CVSS3: 7.8
nvd
больше 5 лет назад

Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.

CVSS3: 7.8
github
больше 3 лет назад

Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.

EPSS

Процентиль: 13%
0.00043
Низкий