CVE-2020-26932

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/10/2020
Last modified:
08/11/2022

Description

debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sympa:sympa:*:*:*:*:*:*:*:* 6.2.40 (excluding)
cpe:2.3:o:debian:debian_linux:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*