4
CVSSv2

CVE-2020-26932

Published: 10/10/2020 Updated: 08/11/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

debian/sympa.postinst for the Debian Sympa package prior to 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sympa sympa

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #971904 sympa: restrict access to sympa_newaliases-wrapper (setuid root) to group sympa (CVE-2020-26932) Package: src:sympa; Maintainer for src:sympa is Debian Sympa team <sympa@packagesdebianorg>; Reported by: Sylvain Beucler <beuc@beucnet> Date: Fri, 9 Oct 2020 12:45:01 UTC Severity: no ...
Several vulnerabilities were discovered in Sympa, a mailing list manager, which could result in local privilege escalation, denial of service or unauthorized access via the SOAP API Additionally to mitigate CVE-2020-26880 the sympa_newaliases-wrapper is no longer installed setuid root by default A new Debconf question is introduced to allow setui ...