
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-26932 affects the Debian Sympa package before version 6.2.40~dfsg-7. The vulnerability exists in the debian/sympa.postinst file, which incorrectly sets permissions mode 4755 for sympa_newaliases-wrapper, instead of the intended mode 4750 that should restrict access to the sympa group (Debian Security, NVD).
The vulnerability is classified with a CVSS v3.1 Base Score of 4.3 (MEDIUM) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N. It is categorized under CWE-732 (Incorrect Permission Assignment for Critical Resource). The issue specifically relates to improper permission settings where the sympa_newaliases-wrapper was configured with world-executable permissions while being setuid root, instead of restricting access to the sympa group (NVD).
The incorrect permission assignment could allow unauthorized users to gain root privileges without first having to escalate to the sympa user, as the wrapper was both setuid root and world-executable (Debian Tracker).
This is a local privilege escalation vulnerability that requires local access to the system. The vulnerability was discovered and reported through the Debian bug tracking system, though there are no public reports of it being actively exploited in the wild (Debian Bugs).
The vulnerability was fixed in Sympa version 6.2.40~dfsg-7 by properly restricting access to sympa_newaliases-wrapper to the sympa group. The fix was included in multiple security updates including DSA-4818-1 for Debian buster and DLA-2401-1 for Debian stretch. Additionally, in later versions, sympa_newaliases-wrapper is no longer installed setuid root by default, with a new Debconf question introduced to allow setuid installations where needed (Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."