CVE-2020-8014

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/06/2020
Last modified:
09/07/2020

Description

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE Tumbleweed kopano-spamd versions prior to 10.0.5-1.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
cpe:2.3:a:opensuse:tumbleweed_kopano-spamd:*:*:*:*:*:*:*:* 10.0.5-1.1 (excluding)


References to Advisories, Solutions, and Tools