CVE-2019-3689

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/09/2019
Last modified:
07/11/2023

Description

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linux-nfs:nfs-utils:*:*:*:*:*:*:*:* 1.3.0-34.18.1 (including)
cpe:2.3:o:suse:linux_enterprise_server:12:*:*:*:*:*:*:*
cpe:2.3:a:linux-nfs:nfs-utils:*:*:*:*:*:*:*:* 2.1.1-6.10.2 (including)
cpe:2.3:o:suse:linux_enterprise_server:15:*:*:*:*:*:*:*