Medium severity5.5NVD Advisory· Published Aug 13, 2020· Updated Jun 17, 2026
CVE-2020-24332
CVE-2020-24332
Description
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- TrouSerS/TrouSerSdescription
- osv-coords4 versionspkg:rpm/almalinux/trouserspkg:rpm/almalinux/trousers-develpkg:rpm/almalinux/trousers-libpkg:rpm/opensuse/trousers&distro=openSUSE%20Tumbleweed
< 0.3.15-1.el8+ 3 more
- (no CPE)range: < 0.3.15-1.el8
- (no CPE)range: < 0.3.15-1.el8
- (no CPE)range: < 0.3.15-1.el8
- (no CPE)range: < 0.3.15-1.7
Patches
Vulnerability mechanics
References
5- seclists.org/oss-sec/2020/q2/att-135/tcsd_fixes.patchnvdMailing ListPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2020/08/14/1nvdExploitMailing ListThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- sourceforge.net/p/trousers/mailman/message/37015817/nvdExploitMailing ListMitigationThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SSDL7COIFCZQMUBNAASNMKMX7W5JUHRD/nvd
News mentions
0No linked articles in our index yet.