Vulnerability Description
Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sympa | Sympa | <= 6.2.56 |
| Fedoraproject | Fedora | 32 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://github.com/sympa-community/sympa/issues/1009Third Party Advisory
- https://github.com/sympa-community/sympa/issues/943#issuecomment-704779420Third Party Advisory
- https://github.com/sympa-community/sympa/issues/943#issuecomment-704842235Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/11/msg00015.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://github.com/sympa-community/sympa/issues/1009Third Party Advisory
- https://github.com/sympa-community/sympa/issues/943#issuecomment-704779420Third Party Advisory
- https://github.com/sympa-community/sympa/issues/943#issuecomment-704842235Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/11/msg00015.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2020-26880?
CVE-2020-26880 is a vulnerability with a CVSS score of 7.8 (HIGH). Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it thro...
How severe is CVE-2020-26880?
CVE-2020-26880 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26880?
Check the references section above for vendor advisories and patch information. Affected products include: Sympa Sympa, Fedoraproject Fedora, Debian Debian Linux.