Candidate: CVE-2020-8032 PublicDate: 2021-02-25 10:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8032 https://bugzilla.suse.com/show_bug.cgi?id=1180669 Description: A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows local attackers to escalate to root. This issue affects: openSUSE Factory cyrus-sasl version 2.1.27-4.2 and prior versions. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H [7.0 HIGH] Patches_cyrus-sasl2: upstream_cyrus-sasl2: not-affected (debian: openSUSE specific packaging issue) precise/esm_cyrus-sasl2: ignored (end of ESM support, was needs-triage) trusty_cyrus-sasl2: ignored (out of standard support) trusty/esm_cyrus-sasl2: needs-triage xenial_cyrus-sasl2: ignored (end of standard support, was needs-triage) esm-infra/xenial_cyrus-sasl2: needs-triage bionic_cyrus-sasl2: needs-triage focal_cyrus-sasl2: needs-triage groovy_cyrus-sasl2: ignored (reached end-of-life) hirsute_cyrus-sasl2: ignored (reached end-of-life) impish_cyrus-sasl2: needs-triage jammy_cyrus-sasl2: needs-triage devel_cyrus-sasl2: needs-triage