// For flags

CVE-2020-8019

syslog-ng: Local privilege escalation from new to root in %post

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module for Legacy Software 12, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server for SAP 12-SP1; openSUSE Backports SLE-15-SP1, openSUSE Leap 15.1 allowed local attackers controlling the user news to escalate their privileges to root. This issue affects: SUSE Linux Enterprise Debuginfo 11-SP3 syslog-ng versions prior to 2.0.9-27.34.40.5.1. SUSE Linux Enterprise Debuginfo 11-SP4 syslog-ng versions prior to 2.0.9-27.34.40.5.1. SUSE Linux Enterprise Module for Legacy Software 12 syslog-ng versions prior to 3.6.4-12.8.1. SUSE Linux Enterprise Point of Sale 11-SP3 syslog-ng versions prior to 2.0.9-27.34.40.5.1. SUSE Linux Enterprise Server 11-SP4-LTSS syslog-ng versions prior to 2.0.9-27.34.40.5.1. SUSE Linux Enterprise Server for SAP 12-SP1 syslog-ng versions prior to 3.6.4-12.8.1. openSUSE Backports SLE-15-SP1 syslog-ng versions prior to 3.19.1-bp151.4.6.1. openSUSE Leap 15.1 syslog-ng versions prior to 3.19.1-lp151.3.6.1.

Una vulnerabilidad de Seguimiento de Enlace Simbólico de UNIX (Symlink), en el paquete de syslog-ng de SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module for Legacy Software versión 12, SUSE Linux Enterprise Point of Sale versión 11- SP3, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server for SAP versión 12-SP1; openSUSE Backports versión SLE-15-SP1, openSUSE Leap versión 15.1, permitió a atacantes locales que controlaban las noticias de usuarios escalar sus privilegios a root. Este problema afecta a: syslog-ng de SUSE Linux Enterprise Debuginfo 11-SP3 versiones anteriores a 2.0.9-27.34.40.5.1. syslog-ng de SUSE Linux Enterprise Debuginfo 11-SP4 versiones anteriores a 2.0.9-27.34.40.5.1. syslog-ng de SUSE Linux Enterprise Module for Legacy Software 12 versiones anteriores a 3.6.4-12.8.1. syslog-ng de SUSE Linux Enterprise Point of Sale 11-SP3 versiones anteriores a 2.0.9-27.34.40.5.1. syslog-ng de SUSE Linux Enterprise Server 11-SP4-LTSS versiones anteriores a 2.0.9-27.34.40.5.1. syslog-ng de SUSE Linux Enterprise Server for SAP 12-SP1 versiones anteriores a 3.6.4-12.8.1. syslog-ng de OpenSUSE Backports SLE-15-SP1 versiones anteriores a 3.19.1-bp151.4.6.1. syslog-ng de openSUSE Leap 15.1 versiones anteriores a 3.19.1-lp151.3.6.1

*Credits: Johannes Segitz of SUSE
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-27 CVE Reserved
  • 2020-06-29 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-17 CVE Updated
  • 2024-09-17 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-61: UNIX Symbolic Link (Symlink) Following
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Oneidentity
Search vendor "Oneidentity"
Syslog-ng
Search vendor "Oneidentity" for product "Syslog-ng"
< 2.0.9-27.34.40.5.1
Search vendor "Oneidentity" for product "Syslog-ng" and version " < 2.0.9-27.34.40.5.1"
-
Affected
in Suse
Search vendor "Suse"
Linux Enterprise Debuginfo
Search vendor "Suse" for product "Linux Enterprise Debuginfo"
11
Search vendor "Suse" for product "Linux Enterprise Debuginfo" and version "11"
sp3
Safe
Oneidentity
Search vendor "Oneidentity"
Syslog-ng
Search vendor "Oneidentity" for product "Syslog-ng"
< 2.0.9-27.34.40.5.1
Search vendor "Oneidentity" for product "Syslog-ng" and version " < 2.0.9-27.34.40.5.1"
-
Affected
in Suse
Search vendor "Suse"
Linux Enterprise Debuginfo
Search vendor "Suse" for product "Linux Enterprise Debuginfo"
11
Search vendor "Suse" for product "Linux Enterprise Debuginfo" and version "11"
sp4
Safe
Oneidentity
Search vendor "Oneidentity"
Syslog-ng
Search vendor "Oneidentity" for product "Syslog-ng"
< 3.6.4-12.8.1
Search vendor "Oneidentity" for product "Syslog-ng" and version " < 3.6.4-12.8.1"
-
Affected
in Suse
Search vendor "Suse"
Linux Enterprise Module For Legacy
Search vendor "Suse" for product "Linux Enterprise Module For Legacy"
12
Search vendor "Suse" for product "Linux Enterprise Module For Legacy" and version "12"
-
Safe
Oneidentity
Search vendor "Oneidentity"
Syslog-ng
Search vendor "Oneidentity" for product "Syslog-ng"
< 2.0.9-27.34.40.5.1
Search vendor "Oneidentity" for product "Syslog-ng" and version " < 2.0.9-27.34.40.5.1"
-
Affected
in Suse
Search vendor "Suse"
Linux Enterprise Point Of Sale
Search vendor "Suse" for product "Linux Enterprise Point Of Sale"
11
Search vendor "Suse" for product "Linux Enterprise Point Of Sale" and version "11"
sp3
Safe
Oneidentity
Search vendor "Oneidentity"
Syslog-ng
Search vendor "Oneidentity" for product "Syslog-ng"
< 2.0.9-27.34.40.5.1
Search vendor "Oneidentity" for product "Syslog-ng" and version " < 2.0.9-27.34.40.5.1"
-
Affected
in Suse
Search vendor "Suse"
Linux Enterprise Server
Search vendor "Suse" for product "Linux Enterprise Server"
11
Search vendor "Suse" for product "Linux Enterprise Server" and version "11"
sp4, ltss
Safe
Oneidentity
Search vendor "Oneidentity"
Syslog-ng
Search vendor "Oneidentity" for product "Syslog-ng"
< 3.6.4-12.8.1
Search vendor "Oneidentity" for product "Syslog-ng" and version " < 3.6.4-12.8.1"
-
Affected
in Suse
Search vendor "Suse"
Linux Enterprise Server
Search vendor "Suse" for product "Linux Enterprise Server"
12
Search vendor "Suse" for product "Linux Enterprise Server" and version "12"
sp1, sap
Safe
Oneidentity
Search vendor "Oneidentity"
Syslog-ng
Search vendor "Oneidentity" for product "Syslog-ng"
< 3.19.1-bp151.4.6.1
Search vendor "Oneidentity" for product "Syslog-ng" and version " < 3.19.1-bp151.4.6.1"
-
Affected
in Opensuse
Search vendor "Opensuse"
Backports Sle
Search vendor "Opensuse" for product "Backports Sle"
15.0
Search vendor "Opensuse" for product "Backports Sle" and version "15.0"
sp1
Safe
Oneidentity
Search vendor "Oneidentity"
Syslog-ng
Search vendor "Oneidentity" for product "Syslog-ng"
< 3.19.1-lp151.3.6.1
Search vendor "Oneidentity" for product "Syslog-ng" and version " < 3.19.1-lp151.3.6.1"
-
Affected
in Opensuse
Search vendor "Opensuse"
Leap
Search vendor "Opensuse" for product "Leap"
15.1
Search vendor "Opensuse" for product "Leap" and version "15.1"
-
Safe