Vulnerability Database
Blog
FAQ
Docs
CVE-2020-10936
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2020-10936
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-10936.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-10936
Related
DLA-2401-1
DSA-4818-1
UBUNTU-CVE-2020-10936
USN-4442-1
USN-4442-2
Published
2020-05-27T18:15:12Z
Modified
2024-10-12T05:32:21.334106Z
Severity
7.8 (High)
CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
[none]
Details
Sympa before 6.2.56 allows privilege escalation.
References
https://www.debian.org/security/2020/dsa-4818
https://lists.debian.org/debian-lts-announce/2020/10/msg00012.html
https://sysdream.com/news/lab/2020-05-25-cve-2020-10936-sympa-privileges-escalation-to-root/
https://github.com/sympa-community/sympa/releases
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3J4NZLGAF4ZYK52XEBQDTBNHLGBEPXXN/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3TMQ3CORUOWARALACCBG2SBTIGZ5GY5/
https://sysdream.com/news/lab/
https://usn.ubuntu.com/4442-1/
https://security-tracker.debian.org/tracker/CVE-2020-10936
Affected packages
Debian:11
/
sympa
Package
Name
sympa
Purl
pkg:deb/debian/sympa?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
6.2.40~dfsg-5
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:12
/
sympa
Package
Name
sympa
Purl
pkg:deb/debian/sympa?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
6.2.40~dfsg-5
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:13
/
sympa
Package
Name
sympa
Purl
pkg:deb/debian/sympa?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
6.2.40~dfsg-5
Ecosystem specific
{ "urgency": "not yet assigned" }
Git
/
github.com/sympa-community/sympa
Affected ranges
Type
GIT
Repo
https://github.com/sympa-community/sympa
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
0fa537621ffcdfa9702e2e4cf5ec4807dc6d44cf
Affected versions
6.*
6.2.16
6.2.17b.1
6.2.17b.2
6.2.18
6.2.19b.1
6.2.19b.2
6.2.20
6.2.22
6.2.23b.1
6.2.23b.2
6.2.23b.3
6.2.24
6.2.25b.1
6.2.25b.2
6.2.25b.3
6.2.26
6.2.28
6.2.30
6.2.32
6.2.33b.1
6.2.33b.2
6.2.34
6.2.35b.1
6.2.36
6.2.37b.1
6.2.37b.2
6.2.37b.3
6.2.38
6.2.40
6.2.41b.1
6.2.41b.2
6.2.42
6.2.43b.1
6.2.43b.2
6.2.44
6.2.45b.1
6.2.45b.2
6.2.45b.3
6.2.46
6.2.48
6.2.49b.1
6.2.49b.2
6.2.49b.3
6.2.50
6.2.52
6.2.54
CVE-2020-10936 - OSV