Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3698

Опубликовано: 28 фев. 2020
Источник: nvd
CVSS3: 5.7
CVSS3: 7
CVSS2: 6.9
EPSS Низкий

Описание

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11 nagios version 3.0.6-1.25.36.3.1 and prior versions. openSUSE Factory nagios version 4.4.5-2.1 and prior versions.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:nagios:nagios:*:*:*:*:*:*:*:*
Версия до 3.5.1 (исключая)
cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:a:nagios:nagios:*:*:*:*:*:*:*:*
Версия до 3.0.6 (исключая)
cpe:2.3:o:suse:linux_enterprise_server:11:-:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.00176
Низкий

5.7 Medium

CVSS3

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-59
CWE-59

Связанные уязвимости

CVSS3: 5.7
ubuntu
почти 6 лет назад

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11 nagios version 3.0.6-1.25.36.3.1 and prior versions. openSUSE Factory nagios version 4.4.5-2.1 and prior versions.

github
больше 3 лет назад

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11 nagios version 3.0.6-1.25.36.3.1 and prior versions. openSUSE Factory nagios version 4.4.5-2.1 and prior versions.

suse-cvrf
больше 1 года назад

Security update for SUSE Manager Client Tools Beta

suse-cvrf
почти 6 лет назад

Security update for nagios

EPSS

Процентиль: 39%
0.00176
Низкий

5.7 Medium

CVSS3

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-59
CWE-59