Vulnerability Name: | CVE-2020-8018 (CCN-181374) | ||||||||||||
Assigned: | 2020-04-08 | ||||||||||||
Published: | 2020-04-08 | ||||||||||||
Updated: | 2020-05-12 | ||||||||||||
Summary: | A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server 15 SP1 allows local attackers with the UID 1000 to escalate to root due to a /etc directory owned by the user This issue affects: SUSE Linux Enterprise Server 15 SP1 SLES15-SP1-CAP-Deployment-BYOS version 1.0.1 and prior versions; SLES15-SP1-CHOST-BYOS versions prior to 1.0.3 and prior versions; | ||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-276 | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-8018 Source: CCN Type: Bugzilla Bug 1163813 (CVE-2020-8018) VUL-0: CVE-2020-8018: User owned /etc in SLES15-SP1-CHOST-BYOS Source: CONFIRM Type: Issue Tracking, Permissions Required https://bugzilla.suse.com/show_bug.cgi?id=1163813 Source: XF Type: UNKNOWN suse-cve20208018-priv-esc(181374) | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |