CVE-2020-25860

NameCVE-2020-25860
DescriptionThe install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for installation. An attacker who can modify the update file just before it is reopened can install arbitrary code on the device.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rauc (PTS)bullseye1.5.1-1fixed
bookworm1.8-2fixed
sid, trixie1.11.3-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
raucsource(unstable)1.5-1

Notes

https://github.com/rauc/rauc/security/advisories/GHSA-cgf3-h62j-w9vv

Search for package or bug name: Reporting problems