CVE-2020-8013
Last modified
CVE-2020-8013 is a low-severity vulnerability rated 2.5/10 on the CVSS scale. A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 11 set permissions intended for specific binaries on other binaries because it erroneously followed symlinks. The symlinks can't be controlled by attackers on default systems, so exploitation is difficult. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 11 set permissions intended for specific binaries on other binaries because it erroneously followed symlinks. The symlinks can't be controlled by attackers on default systems, so exploitation is difficult. This issue affects: SUSE Linux Enterprise Server 12 permissions versions prior to 2015.09.28.1626-17.27.1. SUSE Linux Enterprise Server 15 permissions versions prior to 20181116-9.23.1. SUSE Linux Enterprise Server 11 permissions versions prior to 2013.1.7-0.6.12.1.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Suse | Linux Enterprise Server | 11 |
| Suse | Linux Enterprise Server | 12 |
| Suse | Linux Enterprise Server | 15 |
| Opensuse | Leap | 15.1 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00010.htmlMailing List, Vendor Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1163922Issue Tracking, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00010.htmlMailing List, Vendor Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1163922Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8013?
How severe is CVE-2020-8013?
How do I fix CVE-2020-8013?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-8006The server in Circontrol Raption through 5.11.2 has a pre-au…8.8
- CVE-2020-8007The pwrstudio web application of EV Charger (in the server i…9.8
- CVE-2020-8009AVB MOTU devices through 2020-01-22 allow /.. Directory Trav…7.5
- CVE-2020-8010CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.…9.8
- CVE-2020-8011CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.…7.5
- CVE-2020-8012CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.…9.8
- CVE-2020-8014A UNIX Symbolic Link (Symlink) Following vulnerability in th…7.8
- CVE-2020-8015A UNIX Symbolic Link (Symlink) Following vulnerability in th…7.8
- CVE-2020-8016A Race Condition Enabling Link Following vulnerability in th…7
- CVE-2020-8017A Race Condition Enabling Link Following vulnerability in th…6.3
- CVE-2020-8018A Incorrect Default Permissions vulnerability in the SLES15-…7.8
- CVE-2020-8019A UNIX Symbolic Link (Symlink) Following vulnerability in th…7.8
Are you affected by CVE-2020-8013?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
