vulnerability

SUSE: CVE-2020-8025: SUSE Linux Security Advisory

Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
Aug 7, 2020
Added
Apr 22, 2021
Modified
Feb 4, 2022

Description

A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to unintended settings. This issue affects: SUSE Linux Enterprise Server 12-SP4 permissions versions prior to 20170707-3.24.1. SUSE Linux Enterprise Server 15-LTSS permissions versions prior to 20180125-3.27.1. SUSE Linux Enterprise Server for SAP 15 permissions versions prior to 20180125-3.27.1. openSUSE Leap 15.1 permissions versions prior to 20181116-lp151.4.24.1. openSUSE Tumbleweed permissions versions prior to 20200624.

Solution(s)

suse-upgrade-libpcp-develsuse-upgrade-libpcp3suse-upgrade-libpcp_gui2suse-upgrade-libpcp_import1suse-upgrade-libpcp_mmv1suse-upgrade-libpcp_trace2suse-upgrade-libpcp_web1suse-upgrade-pcpsuse-upgrade-pcp-confsuse-upgrade-pcp-develsuse-upgrade-pcp-docsuse-upgrade-pcp-import-iostat2pcpsuse-upgrade-pcp-import-mrtg2pcpsuse-upgrade-pcp-import-sar2pcpsuse-upgrade-perl-pcp-logimportsuse-upgrade-perl-pcp-logsummarysuse-upgrade-perl-pcp-mmvsuse-upgrade-perl-pcp-pmdasuse-upgrade-permissionssuse-upgrade-permissions-zypp-pluginsuse-upgrade-python-pcp
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.