Логотип exploitDog
bind:CVE-2020-13882
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-13882

Количество 4

Количество 4

ubuntu логотип

CVE-2020-13882

больше 5 лет назад

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker can set up a log and report file, and control that up to the point where the specific routine is doing its check. After that, the file can be removed, recreated, and used for additional attacks.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2020-13882

больше 5 лет назад

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker can set up a log and report file, and control that up to the point where the specific routine is doing its check. After that, the file can be removed, recreated, and used for additional attacks.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2020-13882

больше 5 лет назад

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TO ...

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-fgc5-qjvv-cffv

больше 3 лет назад

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker can set up a log and report file, and control that up to the point where the specific routine is doing its check. After that, the file can be removed, recreated, and used for additional attacks.

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-13882

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker can set up a log and report file, and control that up to the point where the specific routine is doing its check. After that, the file can be removed, recreated, and used for additional attacks.

CVSS3: 4.2
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-13882

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker can set up a log and report file, and control that up to the point where the specific routine is doing its check. After that, the file can be removed, recreated, and used for additional attacks.

CVSS3: 4.2
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-13882

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TO ...

CVSS3: 4.2
0%
Низкий
больше 5 лет назад
github логотип
GHSA-fgc5-qjvv-cffv

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker can set up a log and report file, and control that up to the point where the specific routine is doing its check. After that, the file can be removed, recreated, and used for additional attacks.

CVSS3: 4.2
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу