VYPR
Medium severity4.3NVD Advisory· Published Oct 10, 2020· Updated Jun 17, 2026

CVE-2020-26932

CVE-2020-26932

Description

debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)

Affected products

5
  • Sympa/Sympa2 versions
    cpe:2.3:a:sympa:sympa:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sympa:sympa:*:*:*:*:*:*:*:*range: <6.2.40
    • (no CPE)range: <6.2.40~dfsg-7
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • Debian/Sympadescription
  • Debian/Sympallm-fuzzy
    Range: <6.2.40~dfsg-7

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.