First published: Thu Apr 02 2020(Updated: )
A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users in group mktex to delete arbitrary files on the system This issue affects: SUSE Linux Enterprise Module for Desktop Applications 15-SP1 texlive-filesystem versions prior to 2017.135-9.5.1. SUSE Linux Enterprise Software Development Kit 12-SP4 texlive-filesystem versions prior to 2013.74-16.5.1. SUSE Linux Enterprise Software Development Kit 12-SP5 texlive-filesystem versions prior to 2013.74-16.5.1. openSUSE Leap 15.1 texlive-filesystem versions prior to 2017.135-lp151.8.3.1.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Opensuse Texlive-filesystem | <2017.135-9.5.1 | |
SUSE Linux Enterprise Desktop | =15-sp1 | |
Opensuse Texlive-filesystem | <2013.74-16.5.1 | |
SUSE Linux Enterprise Software Development Kit | =12-sp4 | |
SUSE Linux Enterprise Software Development Kit | =12-sp5 | |
Opensuse Texlive-filesystem | ||
SUSE Linux Enterprise Desktop | =15 | |
Opensuse Texlive-filesystem | <2017.135-lp151.8.3.1 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-8017.
CVE-2020-8017 has a severity level of 6.3 (medium).
CVE-2020-8017 affects texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5, and openSUSE Leap 15.1.
There is currently no known fix for CVE-2020-8017. It is recommended to follow the provided references for more information and updates.
More information about CVE-2020-8017 can be found on the OpenSuse security announcement and the SUSE bugzilla page provided in the references.