Rapid7 Vulnerability & Exploit Database

SUSE: CVE-2020-8025: SUSE Linux Security Advisory

Back to Search

SUSE: CVE-2020-8025: SUSE Linux Security Advisory

Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
08/07/2020
Created
04/24/2021
Added
04/22/2021
Modified
02/04/2022

Description

A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to unintended settings. This issue affects: SUSE Linux Enterprise Server 12-SP4 permissions versions prior to 20170707-3.24.1. SUSE Linux Enterprise Server 15-LTSS permissions versions prior to 20180125-3.27.1. SUSE Linux Enterprise Server for SAP 15 permissions versions prior to 20180125-3.27.1. openSUSE Leap 15.1 permissions versions prior to 20181116-lp151.4.24.1. openSUSE Tumbleweed permissions versions prior to 20200624.

Solution(s)

  • suse-upgrade-libpcp-devel
  • suse-upgrade-libpcp3
  • suse-upgrade-libpcp_gui2
  • suse-upgrade-libpcp_import1
  • suse-upgrade-libpcp_mmv1
  • suse-upgrade-libpcp_trace2
  • suse-upgrade-libpcp_web1
  • suse-upgrade-pcp
  • suse-upgrade-pcp-conf
  • suse-upgrade-pcp-devel
  • suse-upgrade-pcp-doc
  • suse-upgrade-pcp-import-iostat2pcp
  • suse-upgrade-pcp-import-mrtg2pcp
  • suse-upgrade-pcp-import-sar2pcp
  • suse-upgrade-perl-pcp-logimport
  • suse-upgrade-perl-pcp-logsummary
  • suse-upgrade-perl-pcp-mmv
  • suse-upgrade-perl-pcp-pmda
  • suse-upgrade-permissions
  • suse-upgrade-permissions-zypp-plugin
  • suse-upgrade-python-pcp

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;