CVE-2021-20001

NameCVE-2021-20001
DescriptionIt was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2918-1, DSA-5072-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
debian-edu-config (PTS)buster, buster (security)2.10.65+deb10u8fixed
bullseye2.11.56+deb11u4fixed
bullseye (security)2.11.56+deb11u3fixed
bookworm2.12.44~deb12u1fixed
sid, trixie2.12.44fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
debian-edu-configsourcestretch1.929+deb9u5DLA-2918-1
debian-edu-configsourcebuster2.10.65+deb10u8DSA-5072-1
debian-edu-configsourcebullseye2.11.56+deb11u3DSA-5072-1
debian-edu-configsource(unstable)2.12.16

Notes

https://salsa.debian.org/debian-edu/debian-edu-config/-/commit/4d39a5888d193567704238f8c035f8d17cfe34e5

Search for package or bug name: Reporting problems