CVE-2020-8013
Last modified
CVE-2020-8013 is a low-severity vulnerability rated 2.5/10 on the CVSS scale. A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 11 set permissions intended for specific binaries on other binaries because it erroneously followed symlinks. The symlinks can't be controlled by attackers on default systems, so exploitation is difficult. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 11 set permissions intended for specific binaries on other binaries because it erroneously followed symlinks. The symlinks can't be controlled by attackers on default systems, so exploitation is difficult. This issue affects: SUSE Linux Enterprise Server 12 permissions versions prior to 2015.09.28.1626-17.27.1. SUSE Linux Enterprise Server 15 permissions versions prior to 20181116-9.23.1. SUSE Linux Enterprise Server 11 permissions versions prior to 2013.1.7-0.6.12.1.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Suse | Linux Enterprise Server | 11 |
| Suse | Linux Enterprise Server | 12 |
| Suse | Linux Enterprise Server | 15 |
| Opensuse | Leap | 15.1 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00010.htmlMailing List, Vendor Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1163922Issue Tracking, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00010.htmlMailing List, Vendor Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1163922Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8013?
How severe is CVE-2020-8013?
How do I fix CVE-2020-8013?
Are you affected by CVE-2020-8013?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
