User owned /etc in SLES15-SP1-CHOST-BYOS
Published May 4, 2020
8.4
HIGHCVSS 3.1
EPSS 0.29%
Description
A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server 15 SP1 allows local attackers with the UID 1000 to escalate to root due to a /etc directory owned by the user This issue affects: SUSE Linux Enterprise Server 15 SP1 SLES15-SP1-CAP-Deployment-BYOS version 1.0.1 and prior versions; SLES15-SP1-CHOST-BYOS versions prior to 1.0.3 and prior versions;
Affected products
-
Affected
- ≥ SLES15-SP1-CAP-Deployment-BYOS, ≤ 1.0.1
- ≥ SLES15-SP1-CHOST-BYOS, ≤ 1.0.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| SUSE | SUSE Linux Enterprise Server 15 SP1 | unknown | Affected
|
- 15
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://bugzilla.suse.com/show_bug.cgi?id=1163813 x_refsource_CONFIRMIssue TrackingPermissions Required
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28931 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1163813 | x_refsource_CONFIRMIssue TrackingPermissions Required | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28931 | Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data