CVE-2020-8014

HIGH

openSUSE Leap 15.1, Tumbleweed - Privilege Escalation

Title source: llm
STIX 2.1

Description

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE Tumbleweed kopano-spamd versions prior to 10.0.5-1.1.

Scores

CVSS v3 7.7
EPSS 0.0003
EPSS Percentile 9.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-61
Status published
Products (2)
opensuse/leap 15.1
opensuse/tumbleweed_kopano-spamd < 10.0.5-1.1
Published Jun 29, 2020
Tracked Since Feb 18, 2026