CVE-2020-8017

A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users in group mktex to delete arbitrary files on the system This issue affects: SUSE Linux Enterprise Module for Desktop Applications 15-SP1 texlive-filesystem versions prior to 2017.135-9.5.1. SUSE Linux Enterprise Software Development Kit 12-SP4 texlive-filesystem versions prior to 2013.74-16.5.1. SUSE Linux Enterprise Software Development Kit 12-SP5 texlive-filesystem versions prior to 2013.74-16.5.1. openSUSE Leap 15.1 texlive-filesystem versions prior to 2017.135-lp151.8.3.1.
TOCTOU
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
opensusetexlive-filesystem
𝑥
< 2017.135-9.5.1
opensusetexlive-filesystem
𝑥
< 2013.74-16.5.1
opensusetexlive-filesystem
𝑥
< 2013.74-16.5.1
opensusetexlive-filesystem
-
opensusetexlive-filesystem
𝑥
< 2017.135-lp151.8.3.1
opensuseleap
15.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
texlive-base
bionic
not-affected
eoan
not-affected
trusty
dne
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libkpathsea6
suse enterprise desktop 15 SP1
6.2.3-11.13.2
fixed
suse enterprise sap 15 SP1
6.2.3-11.13.2
fixed
suse enterprise server 15 SP1
6.2.3-11.13.2
fixed
libptexenc1
suse enterprise desktop 15 SP1
1.3.5-11.13.2
fixed
suse enterprise sap 15 SP1
1.3.5-11.13.2
fixed
suse enterprise server 15 SP1
1.3.5-11.13.2
fixed
libsynctex1
suse enterprise desktop 15 SP1
1.18-11.13.2
fixed
suse enterprise sap 15 SP1
1.18-11.13.2
fixed
suse enterprise server 15 SP1
1.18-11.13.2
fixed
libtexlua52-5
suse enterprise desktop 15 SP1
5.2.4-11.13.2
fixed
suse enterprise sap 15 SP1
5.2.4-11.13.2
fixed
suse enterprise server 15 SP1
5.2.4-11.13.2
fixed
texlive
suse enterprise desktop 15 SP1
2017.20170520-11.13.2
fixed
suse enterprise sap 15 SP1
2017.20170520-11.13.2
fixed
suse enterprise server 15 SP1
2017.20170520-11.13.2
fixed
texlive-bin-devel
suse enterprise desktop 15 SP1
2017.20170520-11.13.2
fixed
suse enterprise sap 15 SP1
2017.20170520-11.13.2
fixed
suse enterprise server 15 SP1
2017.20170520-11.13.2
fixed
texlive-devel
suse enterprise desktop 15 SP1
2017.135-9.12.1
fixed
suse enterprise desktop 15 SP2
2017.135-9.12.1
fixed
suse enterprise desktop 15 SP3
2017.135-9.12.1
fixed
suse enterprise desktop 15 SP4
2021.185-150400.19.4
fixed
suse enterprise desktop 15 SP5
2021.185-150400.19.4
fixed
suse enterprise desktop 15 SP6
2021.185-150400.19.4
fixed
suse enterprise desktop 15 SP7
2021.185-150400.19.4
fixed
suse enterprise sap 15 SP1
2017.135-9.12.1
fixed
suse enterprise sap 15 SP2
2017.135-9.12.1
fixed
suse enterprise sap 15 SP3
2017.135-9.12.1
fixed
suse enterprise sap 15 SP4
2021.185-150400.19.4
fixed
suse enterprise sap 15 SP5
2021.185-150400.19.4
fixed
suse enterprise sap 15 SP6
2021.185-150400.19.4
fixed
suse enterprise sap 15 SP7
2021.185-150400.19.4
fixed
suse enterprise server 15 SP1
2017.135-9.12.1
fixed
suse enterprise server 15 SP2
2017.135-9.12.1
fixed
suse enterprise server 15 SP3
2017.135-9.12.1
fixed
suse enterprise server 15 SP4
2021.185-150400.19.4
fixed
suse enterprise server 15 SP5
2021.185-150400.19.4
fixed
suse enterprise server 15 SP6
2021.185-150400.19.4
fixed
suse enterprise server 15 SP7
2021.185-150400.19.4
fixed
texlive-extratools
suse enterprise desktop 15 SP1
2017.135-9.12.1
fixed
suse enterprise desktop 15 SP2
2017.135-9.12.1
fixed
suse enterprise desktop 15 SP3
2017.135-9.12.1
fixed
suse enterprise desktop 15 SP4
2021.185-150400.19.4
fixed
suse enterprise desktop 15 SP5
2021.185-150400.19.4
fixed
suse enterprise desktop 15 SP6
2021.185-150400.19.4
fixed
suse enterprise desktop 15 SP7
2021.185-150400.19.4
fixed
suse enterprise sap 15 SP1
2017.135-9.12.1
fixed
suse enterprise sap 15 SP2
2017.135-9.12.1
fixed
suse enterprise sap 15 SP3
2017.135-9.12.1
fixed
suse enterprise sap 15 SP4
2021.185-150400.19.4
fixed
suse enterprise sap 15 SP5
2021.185-150400.19.4
fixed
suse enterprise sap 15 SP6
2021.185-150400.19.4
fixed
suse enterprise sap 15 SP7
2021.185-150400.19.4
fixed
suse enterprise server 15 SP1
2017.135-9.12.1
fixed
suse enterprise server 15 SP2
2017.135-9.12.1
fixed
suse enterprise server 15 SP3
2017.135-9.12.1
fixed
suse enterprise server 15 SP4
2021.185-150400.19.4
fixed
suse enterprise server 15 SP5
2021.185-150400.19.4
fixed
suse enterprise server 15 SP6
2021.185-150400.19.4
fixed
suse enterprise server 15 SP7
2021.185-150400.19.4
fixed
texlive-filesystem
suse enterprise desktop 15 SP1
2017.135-9.12.1
fixed
suse enterprise desktop 15 SP2
2017.135-9.12.1
fixed
suse enterprise desktop 15 SP3
2017.135-9.12.1
fixed
suse enterprise desktop 15 SP4
2021.185-150400.19.4
fixed
suse enterprise desktop 15 SP5
2021.185-150400.19.4
fixed
suse enterprise desktop 15 SP6
2021.185-150400.19.4
fixed
suse enterprise desktop 15 SP7
2021.185-150400.19.4
fixed
suse enterprise sap 15 SP1
2017.135-9.12.1
fixed
suse enterprise sap 15 SP2
2017.135-9.12.1
fixed
suse enterprise sap 15 SP3
2017.135-9.12.1
fixed
suse enterprise sap 15 SP4
2021.185-150400.19.4
fixed
suse enterprise sap 15 SP5
2021.185-150400.19.4
fixed
suse enterprise sap 15 SP6
2021.185-150400.19.4
fixed
suse enterprise sap 15 SP7
2021.185-150400.19.4
fixed
suse enterprise server 15 SP1
2017.135-9.12.1
fixed
suse enterprise server 15 SP2
2017.135-9.12.1
fixed
suse enterprise server 15 SP3
2017.135-9.12.1
fixed
suse enterprise server 15 SP4
2021.185-150400.19.4
fixed
suse enterprise server 15 SP5
2021.185-150400.19.4
fixed
suse enterprise server 15 SP6
2021.185-150400.19.4
fixed
suse enterprise server 15 SP7
2021.185-150400.19.4
fixed
texlive-kpathsea-devel
suse enterprise desktop 15 SP1
6.2.3-11.13.2
fixed
suse enterprise sap 15 SP1
6.2.3-11.13.2
fixed
suse enterprise server 15 SP1
6.2.3-11.13.2
fixed
texlive-ptexenc-devel
suse enterprise desktop 15 SP1
1.3.5-11.13.2
fixed
suse enterprise sap 15 SP1
1.3.5-11.13.2
fixed
suse enterprise server 15 SP1
1.3.5-11.13.2
fixed
texlive-synctex-devel
suse enterprise desktop 15 SP1
1.18-11.13.2
fixed
suse enterprise sap 15 SP1
1.18-11.13.2
fixed
suse enterprise server 15 SP1
1.18-11.13.2
fixed
texlive-texlua-devel
suse enterprise desktop 15 SP1
5.2.4-11.13.2
fixed
suse enterprise sap 15 SP1
5.2.4-11.13.2
fixed
suse enterprise server 15 SP1
5.2.4-11.13.2
fixed