Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-13882

Опубликовано: 18 июн. 2020
Источник: nvd
CVSS3: 4.2
CVSS2: 3.7
EPSS Низкий

Описание

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker can set up a log and report file, and control that up to the point where the specific routine is doing its check. After that, the file can be removed, recreated, and used for additional attacks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisofy:lynis:*:*:*:*:*:*:*:*
Версия до 3.0.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

EPSS

Процентиль: 14%
0.00046
Низкий

4.2 Medium

CVSS3

3.7 Low

CVSS2

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 4.2
ubuntu
больше 5 лет назад

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker can set up a log and report file, and control that up to the point where the specific routine is doing its check. After that, the file can be removed, recreated, and used for additional attacks.

CVSS3: 4.2
debian
больше 5 лет назад

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TO ...

CVSS3: 4.2
github
больше 3 лет назад

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker can set up a log and report file, and control that up to the point where the specific routine is doing its check. After that, the file can be removed, recreated, and used for additional attacks.

EPSS

Процентиль: 14%
0.00046
Низкий

4.2 Medium

CVSS3

3.7 Low

CVSS2

Дефекты

CWE-367