A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root. This issue affects: SUSE Linux Enterprise Server 11-SP3 inn version inn-2.4.2-170.21.3.1 and prior versions. openSUSE Backports SLE-15-SP2 inn versions prior to 2.6.2. openSUSE Leap 15.2 inn versions prior to 2.6.2.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Inn | Opensuse | * | 2.4.2-170.21.3.1 (including) |
Inn2 | Ubuntu | bionic | * |
Inn2 | Ubuntu | groovy | * |
Inn2 | Ubuntu | hirsute | * |
Inn2 | Ubuntu | impish | * |
Inn2 | Ubuntu | kinetic | * |
Inn2 | Ubuntu | lunar | * |
Inn2 | Ubuntu | mantic | * |
Inn2 | Ubuntu | trusty | * |
Inn2 | Ubuntu | xenial | * |