Improper Privilege Management in Sympa - CVE-2020-10936
Published: May 27, 2020 / Updated: October 15, 2020
Vulnerability identifier: #VU47650
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10936
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to escalate privileges.
The vulnerability exists due to improper management of privileges within the application. A local user can gain elevated privileges via unknown vectors.
Affected software
Sympa
Fedora
Ubuntu
sympa (Debian package)
sympa (Ubuntu package)
sympa
Fedora
Ubuntu
sympa (Debian package)
sympa (Ubuntu package)
sympa
How to mitigate CVE-2020-10936
Install update from vendor's website.
Sympa - update to 6.2.56
sympa (Debian package) - update to 6.2.40~dfsg-1+deb10u1
sympa (Ubuntu package) - update to 6.1.17~dfsg-1ubuntu0.1~esm1
sympa - addressed in versions 6.2.56-1.el6, 6.2.56-1.el7, 6.2.56-1.fc30, 6.2.56-1.fc31, 6.2.56-1.fc32
sympa (Debian package) - update to 6.2.40~dfsg-1+deb10u1
sympa (Ubuntu package) - update to 6.1.17~dfsg-1ubuntu0.1~esm1
sympa - addressed in versions 6.2.56-1.el6, 6.2.56-1.el7, 6.2.56-1.fc30, 6.2.56-1.fc31, 6.2.56-1.fc32
External References
- https://github.com/sympa-community/sympa/releases
- https://lists.debian.org/debian-lts-announce/2020/10/msg00012.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3J4NZLGAF4ZYK52XEBQDTBNHLGBEPXXN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3TMQ3CORUOWARALACCBG2SBTIGZ5GY5/
- https://sysdream.com/news/lab/
- https://sysdream.com/news/lab/2020-05-25-cve-2020-10936-sympa-privileges-escalation-to-root/
- https://usn.ubuntu.com/4442-1/