High severity7.8NVD Advisory· Published Aug 13, 2020· Updated Jun 17, 2026
CVE-2020-24330
CVE-2020-24330
Description
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- TrouSerS/TrouSerSdescription
- osv-coords8 versionspkg:rpm/almalinux/trouserspkg:rpm/almalinux/trousers-develpkg:rpm/almalinux/trousers-libpkg:rpm/suse/trousers&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/trousers&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/trousers&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/trousers&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/trousers&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015
< 0.3.15-1.el8+ 7 more
- (no CPE)range: < 0.3.15-1.el8
- (no CPE)range: < 0.3.15-1.el8
- (no CPE)range: < 0.3.15-1.el8
- (no CPE)range: < 0.3.14-150000.3.3.1
- (no CPE)range: < 0.3.14-150000.3.3.1
- (no CPE)range: < 0.3.13-3.3.1
- (no CPE)range: < 0.3.14-150000.3.3.1
- (no CPE)range: < 0.3.14-150000.3.3.1
Patches
Vulnerability mechanics
References
5- seclists.org/oss-sec/2020/q2/att-135/tcsd_fixes.patchnvdMailing ListPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2020/08/14/1nvdExploitMailing ListThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- sourceforge.net/p/trousers/mailman/message/37015817/nvdExploitMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SSDL7COIFCZQMUBNAASNMKMX7W5JUHRD/nvd
News mentions
0No linked articles in our index yet.