mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 05:59:31 +02:00
840 B
840 B
CVE-2020-26880
Description
Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.
POC
Reference
- https://github.com/sympa-community/sympa/issues/943#issuecomment-704779420
- https://github.com/sympa-community/sympa/issues/943#issuecomment-704842235