PT-2020-17414 · Opendkim+2 · Opendkim+2

Orlitzky

·

Published

2018-12-10

·

Updated

2020-12-30

·

CVE-2020-35766

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenDKIM versions 2.10.3 and earlier
Description The test suite in libopendkim allows local users to gain privileges via a symlink attack against the /tmp/testkeys file. This issue is related to the files t-testdata.h, t-setup.c, and t-cleanup.c, and is applicable to users who engage in unit-testing the library.
Recommendations For OpenDKIM versions 2.10.3 and earlier, consider restricting access to the test suite to prevent local users from gaining privileges via a symlink attack. As a temporary workaround, avoid using the test suite until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2811
CVE-2020-35766

Affected Products

Alt Linux
Debian
Opendkim