Unrated severityNVD Advisory· Published Feb 11, 2021· Updated Sep 16, 2024
openldap uses fixed paths in /tmp
CVE-2020-8027
Description
A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.37.1. SUSE Linux Enterprise Server for SAP 15 openldap2 versions prior to 2.4.46-9.37.1. openSUSE Leap 15.1 openldap2 versions prior to 2.4.46-lp151.10.18.1. openSUSE Leap 15.2 openldap2 versions prior to 2.4.46-lp152.14.9.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17- osv-coords12 versionspkg:rpm/opensuse/openldap2&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/openldap2&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP1pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP1pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP2pkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/openldap2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015
< 2.4.46-lp151.10.18.1+ 11 more
- (no CPE)range: < 2.4.46-lp151.10.18.1
- (no CPE)range: < 2.4.46-lp152.14.9.1
- (no CPE)range: < 2.4.46-9.37.1
- (no CPE)range: < 2.4.46-9.37.1
- (no CPE)range: < 2.4.46-9.37.1
- (no CPE)range: < 2.4.46-9.37.1
- (no CPE)range: < 2.4.46-9.37.1
- (no CPE)range: < 2.4.46-9.37.1
- (no CPE)range: < 2.4.46-9.37.1
- (no CPE)range: < 2.4.46-9.37.1
- (no CPE)range: < 2.4.46-9.37.1
- (no CPE)range: < 2.4.46-9.37.1
- openSUSE/openSUSE Leap 15.1v5Range: openldap2
- openSUSE/openSUSE Leap 15.2v5Range: openldap2
- Range: openldap2
- Range: openldap2
Patches
Vulnerability mechanics
References
1- bugzilla.suse.com/show_bug.cgimitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.