Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:2771-1

Опубликовано: 24 окт. 2019
Источник: suse-cvrf

Описание

Security update for nfs-utils

This update for nfs-utils fixes the following issues:

  • CVE-2019-3689: Fixed root-owned files stored in insecure /var/lib/nfs. (bsc#1150733)

Список пакетов

SUSE Linux Enterprise Server 12 SP1-LTSS
nfs-client-1.3.0-41.3.1
nfs-doc-1.3.0-41.3.1
nfs-kernel-server-1.3.0-41.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP1
nfs-client-1.3.0-41.3.1
nfs-doc-1.3.0-41.3.1
nfs-kernel-server-1.3.0-41.3.1

Описание

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP1-LTSS:nfs-client-1.3.0-41.3.1
SUSE Linux Enterprise Server 12 SP1-LTSS:nfs-doc-1.3.0-41.3.1
SUSE Linux Enterprise Server 12 SP1-LTSS:nfs-kernel-server-1.3.0-41.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP1:nfs-client-1.3.0-41.3.1

Ссылки
Уязвимость SUSE-SU-2019:2771-1