Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-8025— outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issues

CVSS 6.1 · Medium EPSS 0.05% · P15
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-8025

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issues
Source: NVD (National Vulnerability Database)
Vulnerability Description
A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to unintended settings. This issue affects: SUSE Linux Enterprise Server 12-SP4 permissions versions prior to 20170707-3.24.1. SUSE Linux Enterprise Server 15-LTSS permissions versions prior to 20180125-3.27.1. SUSE Linux Enterprise Server for SAP 15 permissions versions prior to 20180125-3.27.1. openSUSE Leap 15.1 permissions versions prior to 20181116-lp151.4.24.1. openSUSE Tumbleweed permissions versions prior to 20200624.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
不安全的运行时授予权限
Source: NVD (National Vulnerability Database)
Vulnerability Title
openSUSE和SUSE Linux Enterprise Server permissions 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SUSE Linux Enterprise Server是德国SUSE公司的一套企业服务器版Linux操作系统。 openSUSE和SUSE Linux Enterprise Server中的permissions存在安全漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。以下产品及版本受到影响:SUSE Linux Enterprise Server 12-SP4版本(permissions 20170707-3.24.1之前版本),15-LTSS版本(permissions 2018012
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
SUSESUSE Linux Enterprise Server 12-SP4 permissions ~ 20170707-3.24.1 -
SUSESUSE Linux Enterprise Server 15-LTSS permissions ~ 20180125-3.27.1 -
SUSESUSE Linux Enterprise Server for SAP 15 permissions ~ 20180125-3.27.1 -
openSUSEopenSUSE Leap 15.1 permissions ~ 20181116-lp151.4.24.1 -
openSUSEopenSUSE Tumbleweed permissions ~ 20200624 -

II. Public POCs for CVE-2020-8025

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-8025

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2020-8025

No comments yet


Leave a comment