vulnerability

SUSE: CVE-2020-8017: SUSE Linux Security Advisory

Severity
3
CVSS
(AV:L/AC:M/Au:N/C:N/I:P/A:P)
Published
Apr 2, 2020
Added
Jun 10, 2020
Modified
Oct 22, 2021

Description

A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users in group mktex to delete arbitrary files on the system This issue affects: SUSE Linux Enterprise Module for Desktop Applications 15-SP1 texlive-filesystem versions prior to 2017.135-9.5.1. SUSE Linux Enterprise Software Development Kit 12-SP4 texlive-filesystem versions prior to 2013.74-16.5.1. SUSE Linux Enterprise Software Development Kit 12-SP5 texlive-filesystem versions prior to 2013.74-16.5.1. openSUSE Leap 15.1 texlive-filesystem versions prior to 2017.135-lp151.8.3.1.

Solutions

suse-upgrade-libkpathsea6suse-upgrade-libptexenc1suse-upgrade-libsynctex1suse-upgrade-libtexlua52-5suse-upgrade-libtexluajit2suse-upgrade-perl-bibersuse-upgrade-texlivesuse-upgrade-texlive-a2ping-binsuse-upgrade-texlive-accfonts-binsuse-upgrade-texlive-adhocfilelist-binsuse-upgrade-texlive-afm2pl-binsuse-upgrade-texlive-aleph-binsuse-upgrade-texlive-amstex-binsuse-upgrade-texlive-arara-binsuse-upgrade-texlive-asymptote-binsuse-upgrade-texlive-authorindex-binsuse-upgrade-texlive-autosp-binsuse-upgrade-texlive-biber-binsuse-upgrade-texlive-bibexport-binsuse-upgrade-texlive-bibtex-binsuse-upgrade-texlive-bibtex8-binsuse-upgrade-texlive-bibtexu-binsuse-upgrade-texlive-bin-develsuse-upgrade-texlive-bundledoc-binsuse-upgrade-texlive-cachepic-binsuse-upgrade-texlive-checkcites-binsuse-upgrade-texlive-checklistings-binsuse-upgrade-texlive-chktex-binsuse-upgrade-texlive-cjk-gs-integrate-binsuse-upgrade-texlive-cjkutils-binsuse-upgrade-texlive-collection-basicsuse-upgrade-texlive-collection-bibtexextrasuse-upgrade-texlive-collection-binextrasuse-upgrade-texlive-collection-contextsuse-upgrade-texlive-collection-fontsextrasuse-upgrade-texlive-collection-fontsrecommendedsuse-upgrade-texlive-collection-fontutilssuse-upgrade-texlive-collection-formatsextrasuse-upgrade-texlive-collection-gamessuse-upgrade-texlive-collection-htmlxmlsuse-upgrade-texlive-collection-humanitiessuse-upgrade-texlive-collection-langarabicsuse-upgrade-texlive-collection-langchinesesuse-upgrade-texlive-collection-langcjksuse-upgrade-texlive-collection-langcyrillicsuse-upgrade-texlive-collection-langczechslovaksuse-upgrade-texlive-collection-langenglishsuse-upgrade-texlive-collection-langeuropeansuse-upgrade-texlive-collection-langfrenchsuse-upgrade-texlive-collection-langgermansuse-upgrade-texlive-collection-langgreeksuse-upgrade-texlive-collection-langitaliansuse-upgrade-texlive-collection-langjapanesesuse-upgrade-texlive-collection-langkoreansuse-upgrade-texlive-collection-langothersuse-upgrade-texlive-collection-langpolishsuse-upgrade-texlive-collection-langportuguesesuse-upgrade-texlive-collection-langspanishsuse-upgrade-texlive-collection-latexsuse-upgrade-texlive-collection-latexextrasuse-upgrade-texlive-collection-latexrecommendedsuse-upgrade-texlive-collection-luatexsuse-upgrade-texlive-collection-mathsciencesuse-upgrade-texlive-collection-metapostsuse-upgrade-texlive-collection-musicsuse-upgrade-texlive-collection-picturessuse-upgrade-texlive-collection-plaingenericsuse-upgrade-texlive-collection-pstrickssuse-upgrade-texlive-collection-publisherssuse-upgrade-texlive-collection-xetexsuse-upgrade-texlive-context-binsuse-upgrade-texlive-convbkmk-binsuse-upgrade-texlive-crossrefware-binsuse-upgrade-texlive-cslatex-binsuse-upgrade-texlive-csplain-binsuse-upgrade-texlive-ctanify-binsuse-upgrade-texlive-ctanupload-binsuse-upgrade-texlive-ctie-binsuse-upgrade-texlive-cweb-binsuse-upgrade-texlive-cyrillic-bin-binsuse-upgrade-texlive-de-macro-binsuse-upgrade-texlive-detex-binsuse-upgrade-texlive-develsuse-upgrade-texlive-diadia-binsuse-upgrade-texlive-dosepsbin-binsuse-upgrade-texlive-dtl-binsuse-upgrade-texlive-dtxgen-binsuse-upgrade-texlive-dviasm-binsuse-upgrade-texlive-dvicopy-binsuse-upgrade-texlive-dvidvi-binsuse-upgrade-texlive-dviinfox-binsuse-upgrade-texlive-dviljk-binsuse-upgrade-texlive-dvipdfmx-binsuse-upgrade-texlive-dvipng-binsuse-upgrade-texlive-dvipos-binsuse-upgrade-texlive-dvips-binsuse-upgrade-texlive-dvisvgm-binsuse-upgrade-texlive-ebong-binsuse-upgrade-texlive-eplain-binsuse-upgrade-texlive-epspdf-binsuse-upgrade-texlive-epstopdf-binsuse-upgrade-texlive-exceltex-binsuse-upgrade-texlive-extratoolssuse-upgrade-texlive-fig4latex-binsuse-upgrade-texlive-filesystemsuse-upgrade-texlive-findhyph-binsuse-upgrade-texlive-fontinst-binsuse-upgrade-texlive-fontools-binsuse-upgrade-texlive-fontware-binsuse-upgrade-texlive-fragmaster-binsuse-upgrade-texlive-getmap-binsuse-upgrade-texlive-glossaries-binsuse-upgrade-texlive-gregoriotex-binsuse-upgrade-texlive-gsftopk-binsuse-upgrade-texlive-jadetex-binsuse-upgrade-texlive-kotex-utils-binsuse-upgrade-texlive-kpathsea-binsuse-upgrade-texlive-kpathsea-develsuse-upgrade-texlive-lacheck-binsuse-upgrade-texlive-latex-bin-binsuse-upgrade-texlive-latex-git-log-binsuse-upgrade-texlive-latex-papersize-binsuse-upgrade-texlive-latex2man-binsuse-upgrade-texlive-latex2nemeth-binsuse-upgrade-texlive-latexdiff-binsuse-upgrade-texlive-latexfileversion-binsuse-upgrade-texlive-latexindent-binsuse-upgrade-texlive-latexmk-binsuse-upgrade-texlive-latexpand-binsuse-upgrade-texlive-lcdftypetools-binsuse-upgrade-texlive-lilyglyphs-binsuse-upgrade-texlive-listbib-binsuse-upgrade-texlive-listings-ext-binsuse-upgrade-texlive-lollipop-binsuse-upgrade-texlive-ltxfileinfo-binsuse-upgrade-texlive-ltximg-binsuse-upgrade-texlive-lua2dox-binsuse-upgrade-texlive-luaotfload-binsuse-upgrade-texlive-luatex-binsuse-upgrade-texlive-lwarp-binsuse-upgrade-texlive-m-tx-binsuse-upgrade-texlive-make4ht-binsuse-upgrade-texlive-makedtx-binsuse-upgrade-texlive-makeindex-binsuse-upgrade-texlive-match_parens-binsuse-upgrade-texlive-mathspic-binsuse-upgrade-texlive-metafont-binsuse-upgrade-texlive-metapost-binsuse-upgrade-texlive-mex-binsuse-upgrade-texlive-mf2pt1-binsuse-upgrade-texlive-mflua-binsuse-upgrade-texlive-mfware-binsuse-upgrade-texlive-mkgrkindex-binsuse-upgrade-texlive-mkjobtexmf-binsuse-upgrade-texlive-mkpic-binsuse-upgrade-texlive-mltex-binsuse-upgrade-texlive-mptopdf-binsuse-upgrade-texlive-multibibliography-binsuse-upgrade-texlive-musixtex-binsuse-upgrade-texlive-musixtnt-binsuse-upgrade-texlive-omegaware-binsuse-upgrade-texlive-patgen-binsuse-upgrade-texlive-pax-binsuse-upgrade-texlive-pdfbook2-binsuse-upgrade-texlive-pdfcrop-binsuse-upgrade-texlive-pdfjam-binsuse-upgrade-texlive-pdflatexpicscale-binsuse-upgrade-texlive-pdftex-binsuse-upgrade-texlive-pdftools-binsuse-upgrade-texlive-pdfxup-binsuse-upgrade-texlive-pedigree-perl-binsuse-upgrade-texlive-perltex-binsuse-upgrade-texlive-petri-nets-binsuse-upgrade-texlive-pfarrei-binsuse-upgrade-texlive-pkfix-binsuse-upgrade-texlive-pkfix-helper-binsuse-upgrade-texlive-platex-binsuse-upgrade-texlive-pmx-binsuse-upgrade-texlive-pmxchords-binsuse-upgrade-texlive-ps2pk-binsuse-upgrade-texlive-pst-pdf-binsuse-upgrade-texlive-pst2pdf-binsuse-upgrade-texlive-pstools-binsuse-upgrade-texlive-ptex-binsuse-upgrade-texlive-ptex-fontmaps-binsuse-upgrade-texlive-ptex2pdf-binsuse-upgrade-texlive-ptexenc-develsuse-upgrade-texlive-purifyeps-binsuse-upgrade-texlive-pygmentex-binsuse-upgrade-texlive-pythontex-binsuse-upgrade-texlive-rubik-binsuse-upgrade-texlive-scheme-basicsuse-upgrade-texlive-scheme-contextsuse-upgrade-texlive-scheme-fullsuse-upgrade-texlive-scheme-gustsuse-upgrade-texlive-scheme-infraonlysuse-upgrade-texlive-scheme-mediumsuse-upgrade-texlive-scheme-minimalsuse-upgrade-texlive-scheme-smallsuse-upgrade-texlive-scheme-tetexsuse-upgrade-texlive-seetexk-binsuse-upgrade-texlive-splitindex-binsuse-upgrade-texlive-srcredact-binsuse-upgrade-texlive-sty2dtx-binsuse-upgrade-texlive-svn-multi-binsuse-upgrade-texlive-synctex-binsuse-upgrade-texlive-synctex-develsuse-upgrade-texlive-tetex-binsuse-upgrade-texlive-tex-binsuse-upgrade-texlive-tex4ebook-binsuse-upgrade-texlive-tex4ht-binsuse-upgrade-texlive-texconfig-binsuse-upgrade-texlive-texcount-binsuse-upgrade-texlive-texdef-binsuse-upgrade-texlive-texdiff-binsuse-upgrade-texlive-texdirflatten-binsuse-upgrade-texlive-texdoc-binsuse-upgrade-texlive-texfot-binsuse-upgrade-texlive-texliveonfly-binsuse-upgrade-texlive-texloganalyser-binsuse-upgrade-texlive-texlua-develsuse-upgrade-texlive-texluajit-develsuse-upgrade-texlive-texosquery-binsuse-upgrade-texlive-texsis-binsuse-upgrade-texlive-texware-binsuse-upgrade-texlive-thumbpdf-binsuse-upgrade-texlive-tie-binsuse-upgrade-texlive-tpic2pdftex-binsuse-upgrade-texlive-ttfutils-binsuse-upgrade-texlive-typeoutfileinfo-binsuse-upgrade-texlive-ulqda-binsuse-upgrade-texlive-uplatex-binsuse-upgrade-texlive-uptex-binsuse-upgrade-texlive-urlbst-binsuse-upgrade-texlive-velthuis-binsuse-upgrade-texlive-vlna-binsuse-upgrade-texlive-vpe-binsuse-upgrade-texlive-web-binsuse-upgrade-texlive-xdvi-binsuse-upgrade-texlive-xetex-binsuse-upgrade-texlive-xmltex-binsuse-upgrade-texlive-yplan-bin
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.