CVE-2020-26932
published 2020-10-10CVE-2020-26932: debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode…
PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.97%
58.6th percentile
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | sympa | < sympa 6.2.40~dfsg-7 (bookworm) | sympa 6.2.40~dfsg-7 (bookworm) |
| sympa | sympa | < 6.2.40 | 6.2.40 |
| sympa | sympa | >= 0 < 6.2.40~dfsg-7 | 6.2.40~dfsg-7 |
| sympa | sympa | >= 0 < 6.2.40~dfsg-7 | 6.2.40~dfsg-7 |
| sympa | sympa | >= 0 < 6.2.40~dfsg-7 | 6.2.40~dfsg-7 |
| sympa | sympa | >= 0 < 6.2.40~dfsg-7 | 6.2.40~dfsg-7 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rpg9-m4gw-3xwf: debian/sympa
ghsa_unreviewed·2022-05-24
CVE-2020-26932 [MEDIUM] CWE-732 GHSA-rpg9-m4gw-3xwf: debian/sympa
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
OSV
CVE-2020-26932: debian/sympa
osv·2020-10-10·CVSS 4.3
CVE-2020-26932 [MEDIUM] CVE-2020-26932: debian/sympa
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
Debian
CVE-2020-26932: sympa - debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mod...
vendor_debian·2020·CVSS 4.3
CVE-2020-26932 [MEDIUM] CVE-2020-26932: sympa - debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mod...
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
Scope: local
bookworm: resolved (fixed in 6.2.40~dfsg-7)
bullseye: resolved (fixed in 6.2.40~dfsg-7)
forky: resolved (fixed in 6.2.40~dfsg-7)
sid: resolved (fixed in 6.2.40~dfsg-7)
trixie: resolved (fixed in 6.2.40~dfsg-7)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-10
Published