Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3689

Опубликовано: 17 сент. 2019
Источник: redhat
CVSS3: 9.8

Описание

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

Отчет

This issue did not affect the versions of nfs-utils as shipped with Red Hat Enterprise Linux 6, 7, and 8 as /var/lib/nfs directory is owned by root:root.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5nfs-utilsOut of support scope
Red Hat Enterprise Linux 6nfs-utilsNot affected
Red Hat Enterprise Linux 7nfs-utilsNot affected
Red Hat Enterprise Linux 8nfs-utilsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-276
https://bugzilla.redhat.com/show_bug.cgi?id=1850194nfs-utils: root-owned files stored in insecure /var/lib/nfs

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 5.1
ubuntu
больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVSS3: 5.1
nvd
больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVSS3: 5.1
debian
больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and in ...

suse-cvrf
больше 6 лет назад

Security update for nfs-utils

suse-cvrf
больше 6 лет назад

Security update for nfs-utils

9.8 Critical

CVSS3