First published: Fri Oct 09 2020(Updated: )
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/sympa | <=6.2.40~dfsg-6<=6.2.40~dfsg-1 | |
debian/sympa | 6.2.60~dfsg-4 6.2.70~dfsg-2 6.2.72~dfsg-1 | |
Sympa Sympa | <6.2.40 | |
Debian GNU/Linux | ||
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26932 has a moderate severity level due to improper permissions that could lead to unauthorized access.
To fix CVE-2020-26932, update the Sympa package to version 6.2.60~dfsg-4 or later.
Versions of Sympa prior to 6.2.40~dfsg-7 are affected by CVE-2020-26932.
Yes, CVE-2020-26932 affects Debian GNU/Linux 10.0 if using the vulnerable version of the Sympa package.
CVE-2020-26932 states that sympa_newaliases-wrapper should have permissions set to mode 4750.