CVE-2020-7040
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
21/01/2020
Last modified:
27/01/2023
Description
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.)
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:storebackup:storebackup:*:*:*:*:*:*:*:* | 3.5 (including) | |
| cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:opensuse:backports_sle:15.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* | ||
| cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* | ||
| cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
| cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00054.html
- http://www.openwall.com/lists/oss-security/2020/01/20/3
- http://www.openwall.com/lists/oss-security/2020/01/21/2
- http://www.openwall.com/lists/oss-security/2020/01/22/2
- http://www.openwall.com/lists/oss-security/2020/01/22/3
- http://www.openwall.com/lists/oss-security/2020/01/23/1
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2020-7040
- https://lists.debian.org/debian-lts-announce/2020/02/msg00003.html
- https://seclists.org/oss-sec/2020/q1/20
- https://usn.ubuntu.com/4508-1/



