CVE-2020-24332
Summary
| CVE | CVE-2020-24332 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-13 17:15:00 UTC |
| Updated | 2023-11-07 03:19:00 UTC |
| Description | An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| seclists.org/oss-sec/2020/q2/att-135/tcsd_fixes.patch |
MISC |
seclists.org |
Mailing List, Patch, Third Party Advisory |
| [SECURITY] Fedora 33 Update: trousers-0.3.14-4.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Bug 1164472 – VUL-0: CVE-2020-24330: trousers: TrouSerS tcsd privilege escalation tss to root user |
MISC |
bugzilla.suse.com |
Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 33 Update: trousers-0.3.14-4.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| TrouSerS / [TrouSerS-tech] Multiple Security Issues in the TrouSerS tpm1.2
tscd Daemon |
MISC |
sourceforge.net |
Exploit, Mailing List, Mitigation, Third Party Advisory |
| oss-security - Re: [TrouSerS-tech] Multiple Security Issues in the TrouSerS tpm1.2
tscd Daemon |
MLIST |
www.openwall.com |
Exploit, Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159198 Oracle Enterprise Linux Security Update for trousers (ELSA-2021-1627)
- 239325 Red Hat Update for trousers (RHSA-2021:1627)
- 377420 Alibaba Cloud Linux Security Update for trousers (ALINUX3-SA-2022:0091)
- 690530 Free Berkeley Software Distribution (FreeBSD) Security Update for security/trousers (e37a0a7b-e1a7-11ea-9538-0c9d925bbbc0)
- 900245 CBL-Mariner Linux Security Update for trousers 0.3.14
- 901016 Common Base Linux Mariner (CBL-Mariner) Security Update for trousers (6927-1)
- 903288 Common Base Linux Mariner (CBL-Mariner) Security Update for trousers (1817)
- 906241 Common Base Linux Mariner (CBL-Mariner) Security Update for trousers (1817-1)
- 906408 Common Base Linux Mariner (CBL-Mariner) Security Update for trousers (6927-2)
- 940087 AlmaLinux Security Update for trousers (ALSA-2021:1627)
- 960195 Rocky Linux Security Update for trousers (RLSA-2021:1627)