Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-3689

Опубликовано: 19 сент. 2019
Источник: ubuntu
Приоритет: low
CVSS2: 10
CVSS3: 5.1

Описание

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

РелизСтатусПримечание
bionic

released

1:1.3.4-2.1ubuntu5.3
devel

released

1:1.3.4-2.5ubuntu5
disco

ignored

end of life
eoan

released

1:1.3.4-2.5ubuntu2.1
esm-infra-legacy/trusty

needed

esm-infra/bionic

released

1:1.3.4-2.1ubuntu5.3
esm-infra/focal

released

1:1.3.4-2.5ubuntu3.3
esm-infra/xenial

released

1:1.2.8-9ubuntu12.3
focal

released

1:1.3.4-2.5ubuntu3.3
groovy

released

1:1.3.4-2.5ubuntu5

Показывать по

10 Critical

CVSS2

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVSS3: 5.1
nvd
больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVSS3: 5.1
debian
больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and in ...

suse-cvrf
больше 6 лет назад

Security update for nfs-utils

suse-cvrf
больше 6 лет назад

Security update for nfs-utils

10 Critical

CVSS2

5.1 Medium

CVSS3