Vulnerability Name:

CVE-2020-8025 (CCN-186407)

Assigned:2020-07-14
Published:2020-07-14
Updated:2020-08-12
Summary:A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to unintended settings. This issue affects: SUSE Linux Enterprise Server 12-SP4 permissions versions prior to 20170707-3.24.1. SUSE Linux Enterprise Server 15-LTSS permissions versions prior to 20180125-3.27.1. SUSE Linux Enterprise Server for SAP 15 permissions versions prior to 20180125-3.27.1. openSUSE Leap 15.1 permissions versions prior to 20181116-lp151.4.24.1. openSUSE Tumbleweed permissions versions prior to 20200624.
CVSS v3 Severity:9.3 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
8.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
6.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L)
5.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-279
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2020-8025

Source: CCN
Type: Bugzilla - Bug 1171883
(CVE-2020-8025) VUL-0: CVE-2020-8025: pcp: outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issues

Source: CONFIRM
Type: Exploit, Issue Tracking, Vendor Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1171883

Source: XF
Type: UNKNOWN
opensuse-cve20208025-weak-security(186407)

Source: CCN
Type: openSUSE Web site
permissions package for openSUSE

Vulnerable Configuration:Configuration 1:
  • cpe:/o:suse:linux_enterprise_high_performance_computing:15:*:*:*:espos:*:*:*
  • OR cpe:/o:suse:linux_enterprise_high_performance_computing:15:*:*:*:ltss:*:*:*
  • OR cpe:/o:suse:linux_enterprise_server:15:*:*:*:ltss:*:*:*
  • OR cpe:/o:suse:linux_enterprise_server:15:sp1:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_server:15:sp2:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_software_development_kit:12:sp4:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_software_development_kit:12:sp5:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7750
    P
    permissions-20201225-150400.5.16.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3154
    P
    libapr1-1.5.1-4.5.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3438
    P
    augeas-1.10.1-2.6 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94550
    P
    firewalld-0.9.3-150400.7.6 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94784
    P
    permissions-20201225-150400.3.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:271
    P
    permissions-20181224-23.3.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:5263
    P
    Security update for pcp (Moderate)
    2022-05-27
    oval:org.opensuse.security:def:465
    P
    Security update for pcp (Moderate)
    2022-05-03
    oval:org.opensuse.security:def:1200
    P
    Security update for libarchive (Moderate)
    2022-03-24
    oval:org.opensuse.security:def:101263
    P
    dpkg-1.19.0.4-2.30 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72030
    P
    permissions-20181224-23.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101047
    P
    permissions-20181224-23.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62289
    P
    permissions-20181224-23.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:10064
    P
    Security update for pcp (Moderate)
    2021-04-21
    oval:org.opensuse.security:def:96867
    P
    Security update for pcp (Moderate)
    2021-04-21
    oval:org.opensuse.security:def:69450
    P
    Security update for pcp (Moderate)
    2021-04-21
    oval:org.opensuse.security:def:8565
    P
    Security update for pcp (Moderate)
    2021-04-21
    oval:org.opensuse.security:def:70204
    P
    Security update for pcp (Moderate)
    2021-04-21
    oval:org.opensuse.security:def:9310
    P
    Security update for pcp (Moderate)
    2021-04-21
    oval:org.opensuse.security:def:100625
    P
    (Moderate)
    2021-01-22
    oval:org.opensuse.security:def:64527
    P
    Security update for permissions (Moderate)
    2021-01-22
    oval:org.opensuse.security:def:97068
    P
    Security update for permissions (Moderate)
    2021-01-22
    oval:org.opensuse.security:def:99961
    P
    (Moderate)
    2021-01-22
    oval:org.opensuse.security:def:73649
    P
    Security update for permissions (Moderate)
    2021-01-22
    oval:org.opensuse.security:def:107929
    P
    Security update for permissions (Moderate)
    2021-01-22
    oval:org.opensuse.security:def:117444
    P
    Security update for permissions (Moderate)
    2021-01-22
    oval:org.opensuse.security:def:100296
    P
    (Moderate)
    2021-01-22
    BACK
    suse linux enterprise high performance computing 15
    suse linux enterprise high performance computing 15
    suse linux enterprise server 15
    suse linux enterprise server 15 sp1
    suse linux enterprise server 15 sp2
    suse linux enterprise software development kit 12 sp4
    suse linux enterprise software development kit 12 sp5