Логотип exploitDog
bind:"CVE-2019-3689"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2019-3689"

Количество 12

Количество 12

ubuntu логотип

CVE-2019-3689

больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2019-3689

больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-3689

больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVSS3: 5.1
EPSS: Низкий
debian логотип

CVE-2019-3689

больше 6 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and in ...

CVSS3: 5.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2435-1

больше 6 лет назад

Security update for nfs-utils

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2408-1

больше 6 лет назад

Security update for nfs-utils

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2782-1

больше 6 лет назад

Security update for nfs-utils

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2781-1

больше 6 лет назад

Security update for nfs-utils

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2776-1

больше 6 лет назад

Security update for nfs-utils

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2771-1

больше 6 лет назад

Security update for nfs-utils

EPSS: Низкий
github логотип

GHSA-qh2q-m44h-cfm8

больше 3 лет назад

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system if fs.protected_symlinks is not set

EPSS: Низкий
fstec логотип

BDU:2021-00101

больше 6 лет назад

Уязвимость функции nsm_drop_privileges (support/nsm/file.c пакета NFS утилит nfs-utils), связанная с неправельным присвоением стандартных разрешений, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-3689

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVSS3: 5.1
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-3689

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-3689

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

CVSS3: 5.1
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-3689

The nfs-utils package in SUSE Linux Enterprise Server 12 before and in ...

CVSS3: 5.1
0%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2435-1

Security update for nfs-utils

0%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2408-1

Security update for nfs-utils

0%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2782-1

Security update for nfs-utils

0%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2781-1

Security update for nfs-utils

0%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2776-1

Security update for nfs-utils

0%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2771-1

Security update for nfs-utils

0%
Низкий
больше 6 лет назад
github логотип
GHSA-qh2q-m44h-cfm8

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system if fs.protected_symlinks is not set

0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2021-00101

Уязвимость функции nsm_drop_privileges (support/nsm/file.c пакета NFS утилит nfs-utils), связанная с неправельным присвоением стандартных разрешений, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность

CVSS3: 9.8
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу