Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:2781-1

Опубликовано: 25 окт. 2019
Источник: suse-cvrf

Описание

Security update for nfs-utils

This update for nfs-utils fixes the following issues:

  • CVE-2019-3689: Fixed root-owned files stored in insecure /var/lib/nfs. (bsc#1150733)

Список пакетов

HPE Helion OpenStack 8
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-Azure-BYOS
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-Azure-Basic-On-Demand
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-Azure-HPC-BYOS
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-Azure-HPC-On-Demand
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-Azure-SAP-BYOS
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-Azure-SAP-On-Demand
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-Azure-Standard-On-Demand
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-EC2-BYOS
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-EC2-On-Demand
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-EC2-SAP-BYOS
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-EC2-SAP-On-Demand
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-GCE-BYOS
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-GCE-On-Demand
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-GCE-SAP-BYOS
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-GCE-SAP-On-Demand
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-OCI-BYOS-BYOS
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Enterprise Storage 4
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Enterprise Storage 5
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Linux Enterprise Desktop 12 SP4
nfs-client-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Linux Enterprise Server 12 SP2-BCL
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Linux Enterprise Server 12 SP2-LTSS
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Linux Enterprise Server 12 SP3-BCL
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Linux Enterprise Server 12 SP3-LTSS
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Linux Enterprise Server 12 SP4
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Linux Enterprise Server 12 SP5
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE OpenStack Cloud 7
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE OpenStack Cloud 8
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1
SUSE OpenStack Cloud Crowbar 8
nfs-client-1.3.0-34.22.1
nfs-doc-1.3.0-34.22.1
nfs-kernel-server-1.3.0-34.22.1

Описание

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.


Затронутые продукты
HPE Helion OpenStack 8:nfs-client-1.3.0-34.22.1
HPE Helion OpenStack 8:nfs-doc-1.3.0-34.22.1
HPE Helion OpenStack 8:nfs-kernel-server-1.3.0-34.22.1
Image SLES12-SP5-Azure-BYOS:nfs-client-1.3.0-34.22.1

Ссылки
Уязвимость SUSE-SU-2019:2781-1