CVE-2020-8017: race condition on texlive-filesystem cron job allows for the deletion of unintended files
A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users in group mktex to delete arbitrary files on the system This issue affects: SUSE Linux Enterprise Module for Desktop Applications 15-SP1 texlive-filesystem versions prior to 2017.135-9.5.1. SUSE Linux Enterprise Software Development Kit 12-SP4 texlive-filesystem versions prior to 2013.74-16.5.1. SUSE Linux Enterprise Software Development Kit 12-SP5 texlive-filesystem versions prior to 2013.74-16.5.1. openSUSE Leap 15.1 texlive-filesystem versions prior to 2017.135-lp151.8.3.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
texlive-filesystemto a version that resolves this vulnerability.Fixed in 2017.135-9.5.1 - Upgrade
Upgrade
texlive-filesystemto a version that resolves this vulnerability.Fixed in 2013.74-16.5.1 - Upgrade
Upgrade
texlive-filesystemto a version that resolves this vulnerability.Fixed in 2017.135-lp151.8.3.1
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-8017.
What is the severity of CVE-2020-8017?
CVE-2020-8017 has a severity level of 6.3 (medium).
Which software is affected by CVE-2020-8017?
CVE-2020-8017 affects texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5, and openSUSE Leap 15.1.
How can I fix CVE-2020-8017?
There is currently no known fix for CVE-2020-8017. It is recommended to follow the provided references for more information and updates.
Where can I find more information about CVE-2020-8017?
More information about CVE-2020-8017 can be found on the OpenSuse security announcement and the SUSE bugzilla page provided in the references.