{"id":"MGASA-2020-0336","summary":"Updated python-rstlib packages fix security vulnerability","details":"Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for\n/etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is\nused and thus permissions are not preserved upon editing. An adversary with\nprior access to /etc/target/saveconfig.json could access a later version,\nresulting in a loss of integrity depending on their permission settings\n(CVE-2020-14019).\n","modified":"2026-04-16T04:43:26.402608263Z","published":"2020-08-18T18:47:25Z","upstream":["CVE-2020-14019"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0336.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=27042"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TNMCV2DJJTX345YYBXAMJBXNNVUZQ5UH/"}],"affected":[{"package":{"name":"python-rtslib","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/python-rtslib?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.73-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0336.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}