CVE-2019-3689
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/09/2019
Last modified:
07/11/2023
Description
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:linux-nfs:nfs-utils:*:*:*:*:*:*:*:* | 1.3.0-34.18.1 (including) | |
| cpe:2.3:o:suse:linux_enterprise_server:12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:linux-nfs:nfs-utils:*:*:*:*:*:*:*:* | 2.1.1-6.10.2 (including) | |
| cpe:2.3:o:suse:linux_enterprise_server:15:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00071.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00006.html
- https://bugzilla.suse.com/show_bug.cgi?id=1150733
- https://git.linux-nfs.org/?p=steved/nfs-utils.git%3Ba%3Dcommitdiff%3Bh%3Dfee2cc29e888f2ced6a76990923aef19d326dc0e
- https://lists.debian.org/debian-lts-announce/2019/10/msg00026.html
- https://usn.ubuntu.com/4400-1/



