inn: non-root owned files
Vulnerability Description
A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version 2.6.2-lp152.1.26 and prior versions. openSUSE Tumbleweed inn version 2.6.2-4.2 and prior versions. openSUSE Leap 15.1 inn version 2.5.4-lp151.3.3.1 and prior versions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-8026
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Matthias Gerstner/Johannes Segitz of SUSE
References
- https://bugzilla.suse.com/show_bug.cgi?id=1172573
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00064.html
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00063.html
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00074.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00038.html
More from openSUSE
View All →Affected Vendor
openSUSE
View all reports →