PT-2020-15682 · Trousers+7 · Trousers+7

Matthias Gerstner

·

Published

2020-08-13

·

Updated

2024-08-24

·

CVE-2020-24330

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TrouSerS versions prior to 0.3.14
Description An issue was discovered where the tcsd daemon fails to drop the root gid privilege when no longer needed if it is started with root privileges instead of by the tss user.
Recommendations For versions prior to 0.3.14, ensure the tcsd daemon is started by the tss user instead of with root privileges to prevent the issue.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ALSA-2021:1627
ALT-PU-2021-1148
ALT-PU-2021-1350
ALT-PU-2024-11154
AZL-6925
CESA-2021_1627
CVE-2020-24330
MGASA-2021-0297
RHSA-2021:1627
RHSA-2021_1627
RLSA-2021:1627
SUSE-SU-2022:2798-1
SUSE-SU-2022:2800-1
SUSE-SU-2022_2798-1
SUSE-SU-2022_2800-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Red Hat
Rocky Linux
Suse
Trousers