Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:2672-1

Опубликовано: 11 дек. 2019
Источник: suse-cvrf

Описание

Security update for permissions

This update for permissions fixes the following issues:

  • CVE-2019-3688: Changed wrong ownership in /usr/sbin/pinger to root:squid which could have allowed a squid user to gain persistence by changing the binary (bsc#1093414).
  • CVE-2019-3690: Fixed a privilege escalation through untrusted symbolic links (bsc#1150734).
  • Fixed a regression which caused sagmentation fault (bsc#1157198).

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Список пакетов

openSUSE Leap 15.1
permissions-20181116-lp151.4.9.1
permissions-zypp-plugin-20181116-lp151.4.9.1

Описание

The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by changing the binary


Затронутые продукты
openSUSE Leap 15.1:permissions-20181116-lp151.4.9.1
openSUSE Leap 15.1:permissions-zypp-plugin-20181116-lp151.4.9.1

Ссылки

Описание

The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control over a path that is traversed by chkstat to escalate privileges.


Затронутые продукты
openSUSE Leap 15.1:permissions-20181116-lp151.4.9.1
openSUSE Leap 15.1:permissions-zypp-plugin-20181116-lp151.4.9.1

Ссылки