Files
CVEs-PoC/2020/CVE-2020-8017.md
T
2024-05-25 21:48:12 +02:00

23 lines
2.0 KiB
Markdown

### [CVE-2020-8017](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8017)
![](https://img.shields.io/static/v1?label=Product&message=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015-SP1&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012-SP4&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012-SP5&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=openSUSE%20Leap%2015.1&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=texlive-filesystem%3C%202013.74-16.5.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=texlive-filesystem%3C%202017.135-9.5.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=texlive-filesystem%3C%202017.135-lp151.8.3.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-367%3A%20Time-of-check%20Time-of-use%20(TOCTOU)%20Race%20Condition&color=brighgreen)
### Description
A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users in group mktex to delete arbitrary files on the system This issue affects: SUSE Linux Enterprise Module for Desktop Applications 15-SP1 texlive-filesystem versions prior to 2017.135-9.5.1. SUSE Linux Enterprise Software Development Kit 12-SP4 texlive-filesystem versions prior to 2013.74-16.5.1. SUSE Linux Enterprise Software Development Kit 12-SP5 texlive-filesystem versions prior to 2013.74-16.5.1. openSUSE Leap 15.1 texlive-filesystem versions prior to 2017.135-lp151.8.3.1.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/Live-Hack-CVE/CVE-2020-8017