CVE-2020-24332
5.5
MEDIUM
CVSS 3.1
EPSS 0.55%
Description
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.
How to fix CVE-2020-24332
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/trousers—no fix listed
Is CVE-2020-24332 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |