Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:2408-1

Опубликовано: 29 окт. 2019
Источник: suse-cvrf

Описание

Security update for nfs-utils

This update for nfs-utils fixes the following issues:

  • CVE-2019-3689: Fixed root-owned files stored in insecure /var/lib/nfs. (bsc#1150733)

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
nfs-client-2.1.1-lp150.4.10.1
nfs-doc-2.1.1-lp150.4.10.1
nfs-kernel-server-2.1.1-lp150.4.10.1

Описание

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.


Затронутые продукты
openSUSE Leap 15.0:nfs-client-2.1.1-lp150.4.10.1
openSUSE Leap 15.0:nfs-doc-2.1.1-lp150.4.10.1
openSUSE Leap 15.0:nfs-kernel-server-2.1.1-lp150.4.10.1

Ссылки
Уязвимость openSUSE-SU-2019:2408-1