CVE-2020-8026
published 2020-08-07CVE-2020-8026: A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.36%
28.6th percentile
A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version 2.6.2-lp152.1.26 and prior versions. openSUSE Tumbleweed inn version 2.6.2-4.2 and prior versions. openSUSE Leap 15.1 inn version 2.5.4-lp151.3.3.1 and prior versions.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | inn2 | — | — |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | opensuse_leap_15.1 | inn – 2.5.4-lp151.3.3.1 | — |
| opensuse | opensuse_leap_15.2 | inn – 2.6.2-lp152.1.26 | — |
| opensuse | opensuse_tumbleweed | inn – 2.6.2-4.2 | — |
| opensuse | tumbleweed | <= 2.6.2-4.2 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_debian8.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fm9w-35mc-phwx: A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15
ghsa_unreviewed·2022-05-24
CVE-2020-8026 [HIGH] CWE-276 GHSA-fm9w-35mc-phwx: A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15
A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version 2.6.2-lp152.1.26 and prior versions. openSUSE Tumbleweed inn version 2.6.2-4.2 and prior versions. openSUSE Leap 15.1 inn version 2.5.4-lp151.3.3.1 and prior versions.
Debian
CVE-2020-8026: inn2 - A Incorrect Default Permissions vulnerability in the packaging of inn in openSUS...
vendor_debian·2020·CVSS 8.4
CVE-2020-8026 [HIGH] CVE-2020-8026: inn2 - A Incorrect Default Permissions vulnerability in the packaging of inn in openSUS...
A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affects: openSUSE Leap 15.2 inn version 2.6.2-lp152.1.26 and prior versions. openSUSE Tumbleweed inn version 2.6.2-4.2 and prior versions. openSUSE Leap 15.1 inn version 2.5.4-lp151.3.3.1 and prior versions.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00063.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00074.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00038.htmlhttps://bugzilla.suse.com/show_bug.cgi?id=1172573http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00063.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00074.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00038.htmlhttps://bugzilla.suse.com/show_bug.cgi?id=1172573
2020-08-07
Published