CVE-2020-10737

Published May 27, 2020

Last updated a year ago

Overview

Description
A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.
Source
secalert@redhat.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
6.3
Impact score
5.9
Exploitability score
0.3
Vector string
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
3.7
Impact score
6.4
Exploitability score
1.9
Vector string
AV:L/AC:H/Au:N/C:P/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-362
secalert@redhat.com
CWE-362

Social media

Hype score
Not currently trending

Configurations