MEDIUM 5.5 Microsoft
CVE-2020-24332
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files which could possibly lead to a DoS attack.
Microsoft Security Update 2020-Aug: An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files which could possibly lead to a DoS attack.
Affected Products
- cm1 trousers 0.3.14-7 on CBL Mariner 1.0
- cbl2 trousers 0.3.14-7 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-24332
- https://nvd.nist.gov/vuln/detail/CVE-2020-24332
This medium severity vulnerability with a CVSS score of 5.5 was published on 2020-08-11 via Microsoft. Affected: cm1 trousers 0.3.14-7 on CBL Mariner 1.0, cbl2 trousers 0.3.14-7 on CBL Mariner 2.0.
vulnfeed aggregates 9909 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.