Time-of-check Time-of-use (TOCTOU) Affecting lynis package, versions <3.0.0-1


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.05% (14th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN11-LYNIS-572759
  • published18 Jun 2020
  • disclosed18 Jun 2020

Introduced: 18 Jun 2020

CVE-2020-13882  (opens in a new tab)
CWE-367  (opens in a new tab)

How to fix?

Upgrade Debian:11 lynis to version 3.0.0-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream lynis package and not the lynis package as distributed by Debian. See How to fix? for Debian:11 relevant fixed versions and status.

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker can set up a log and report file, and control that up to the point where the specific routine is doing its check. After that, the file can be removed, recreated, and used for additional attacks.

CVSS Base Scores

version 3.1