CVE-2020-24330

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
trousers_projecttrousers
𝑥
≤ 0.3.14
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
trousers
bullseye
unimportant
bookworm
0.3.15-0.3
fixed
sid
0.3.15-0.4
fixed
trixie
0.3.15-0.4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
trousers
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
ignored
jammy
not-affected
impish
ignored
hirsute
ignored
groovy
ignored
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
dne