Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:2776-1

Опубликовано: 24 окт. 2019
Источник: suse-cvrf

Описание

Security update for nfs-utils

This update for nfs-utils fixes the following issues:

  • CVE-2019-3689: Fixed root-owned files stored in insecure /var/lib/nfs. (bsc#1150733)

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15
nfs-client-2.1.1-6.14.1
nfs-doc-2.1.1-6.14.1
nfs-kernel-server-2.1.1-6.14.1

Описание

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15:nfs-client-2.1.1-6.14.1
SUSE Linux Enterprise Module for Basesystem 15:nfs-doc-2.1.1-6.14.1
SUSE Linux Enterprise Module for Basesystem 15:nfs-kernel-server-2.1.1-6.14.1

Ссылки