AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-10737

MEDIUM · CVSS 6.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-05-27 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.3. See the original NVD description below for full technical details.

CVE
CVE-2020-10737
Severity
MEDIUM
CVSS
6.3
EPSS
0.29%

Original NVD Description

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.

Related CVEs

Other vulnerabilities affecting the same vendor(s)