Learn about CVE-2020-8013, a UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Servers 12, 15, and 11. Find out the impact, affected versions, and mitigation steps.
A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 11 set permissions intended for specific binaries on other binaries because it erroneously followed symlinks. The symlinks can't be controlled by attackers on default systems, so exploitation is difficult.
Understanding CVE-2020-8013
This CVE involves a vulnerability in the permissions setting by chkstat in SUSE Linux Enterprise Server versions 12, 15, and 11.
What is CVE-2020-8013?
The vulnerability allows attackers to set permissions on binaries erroneously by following symlinks, potentially impacting the integrity of the system.
The Impact of CVE-2020-8013
Technical Details of CVE-2020-8013
This section provides more in-depth technical details of the vulnerability.
Vulnerability Description
The vulnerability arises from chkstat setting unintended permissions on binaries due to following symlinks.
Affected Systems and Versions
Exploitation Mechanism
Exploitation is challenging as attackers cannot control the symlinks on default systems.
Mitigation and Prevention
Protect your systems from CVE-2020-8013 with the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates