PT-2020-5139 · Suse · Suse Linux Enterprise Server+1

Malte Kraus

·

Published

2020-02-17

·

Updated

2024-06-15

·

CVE-2020-8013

CVSS v3.1

2.5

Low

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise Server 12 versions prior to 2015.09.28.1626-17.27.1 SUSE Linux Enterprise Server 15 versions prior to 20181116-9.23.1 SUSE Linux Enterprise Server 11 versions prior to 2013.1.7-0.6.12.1
Description A UNIX Symbolic Link (Symlink) Following issue in chkstat affects SUSE Linux Enterprise Server, causing it to set permissions intended for specific binaries on other binaries because it erroneously follows symlinks. However, exploitation is difficult since the symlinks cannot be controlled by attackers on default systems. This issue is related to the incorrect determination of a link before accessing a file, which may allow an attacker to elevate their privileges.
Recommendations For SUSE Linux Enterprise Server 12 versions prior to 2015.09.28.1626-17.27.1, update to a version newer than 2015.09.28.1626-17.27.1 to resolve the issue. For SUSE Linux Enterprise Server 15 versions prior to 20181116-9.23.1, update to a version newer than 20181116-9.23.1 to resolve the issue. For SUSE Linux Enterprise Server 11 versions prior to 2013.1.7-0.6.12.1, update to a version newer than 2013.1.7-0.6.12.1 to resolve the issue.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05735
CVE-2020-8013
OPENSUSE-SU-2020:0302-1
OPENSUSE-SU-2020_0302-1
OPENSUSE-SU-2021:1520-1
OPENSUSE-SU-2021_1520-1
OPENSUSE-SU-2024:11165-1
SUSE-RU-2020:0603-1
SUSE-RU-2020:14304-1
SUSE-SU-2020:0545-1
SUSE-SU-2020:0547-1
SUSE-SU-2020:1163-1
SUSE-SU-2020:14304-1
SUSE-SU-2020_0545-1
SUSE-SU-2020_14304-1
SUSE-SU-2021:2280-1

Affected Products

Suse Linux Enterprise Server
Suse