Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-3689

Опубликовано: 19 сент. 2019
Источник: debian
EPSS Низкий

Описание

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nfs-utilsfixed1:1.3.4-3package
nfs-utilsfixed1:1.3.4-2.5+deb10u1busterpackage
nfs-utilsfixed1:1.3.4-2.1+deb9u1stretchpackage

Примечания

  • https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commitdiff;h=fee2cc29e888f2ced6a76990923aef19d326dc0e

EPSS

Процентиль: 56%
0.00336
Низкий

Связанные уязвимости

CVSS3: 5.1
ubuntu
больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVSS3: 9.8
redhat
больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVSS3: 5.1
nvd
больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

suse-cvrf
больше 6 лет назад

Security update for nfs-utils

suse-cvrf
больше 6 лет назад

Security update for nfs-utils

EPSS

Процентиль: 56%
0.00336
Низкий