SB2021031314 - SUSE update for crmsh
Published: March 13, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Improper Privilege Management (CVE-ID: CVE-2020-35459)
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper privilege management. A local user can call "crm history" (when "crm" is run) and execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
2) Improper Privilege Management (CVE-ID: CVE-2021-3020)
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to unspecified error, related to improper privilege management. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.