CVE-2020-25860

The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for installation. An attacker who can modify the update file just before it is reopened can install arbitrary code on the device.
TOCTOU
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.6 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
VDOOCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
pengutronixrauc
𝑥
< 1.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rauc
bullseye
1.5.1-1
fixed
bookworm
1.8-2
fixed
sid
1.12-1
fixed
trixie
1.12-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rauc
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
ignored
jammy
needs-triage
impish
ignored
hirsute
ignored
groovy
ignored
focal
needs-triage
bionic
dne
xenial
dne
trusty
dne