Back

HIGH

trousers: Local privilege escalation from tss to root

Published Jan 23, 2020

Description

UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.

Affected products

Remediation

Red Hat statement

The trousers versions as shipped as Red Hat Enterprise Linux 5, 6, 7 and 8 are not affected by this issue. The flaw resides on the post transaction scriptlet from the RPM package. This scriptlet doesn't exists on Red Hat Enterprise Linux RPM spec file.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner suse
Published Jan 23, 2020
Updated Sep 16, 2024
Reserved Nov 12, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Nov 25, 2019
Bugzilla 1787080

ENISA EUVD

Assigner suse
Published Jan 23, 2020
Updated Sep 16, 2024

GitHub

No data