CVE Vulnerabilities

CVE-2020-26880

Improper Privilege Management

Published: Oct 07, 2020 | Modified: Nov 07, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Sympa Sympa * 6.2.56 (including)
Sympa Sympa 6.2.57-beta1 (including) 6.2.57-beta1 (including)
Sympa Sympa 6.2.57-beta2 (including) 6.2.57-beta2 (including)

Potential Mitigations

References