CVE-2020-24331 describes a privilege escalation vulnerability in TrouSerS versions up to 0.3.14, affecting Fedora and TrouSerS Project distributions. If the tcsd daemon runs as root, a local attacker with tss user privileges can modify the /etc/tcsd.conf file, potentially leading to high impact on confidentiality, integrity, and availability. This vulnerability has a CVSS score of 7.8 (High), indicating a significant risk. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog, suggesting no active exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.3.14CPE matchmatch criteria | cpe:2.3:a:trousers_project:trousers:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
trousers: tss user still has read and write access to the /etc/tcsd.conf file if tcsd is started as root
Aug 13, 2020An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon).
Aug 11, 2020