Permissions, Privileges, and Access Controls in SUSE Linux - CVE-2019-3689

 

Permissions, Privileges, and Access Controls in SUSE Linux - CVE-2019-3689

Published: October 29, 2019


Vulnerability identifier: #VU22333
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3689
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insecure permissions on the " /var/lib/nfs" directory owned by statd:nogroup in the nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

Successful exploitation of the vulnerability may allow a local user to escalate privileges on the system.


Affected software

SUSE Linux
Opensuse
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
RSA Authentication Manager
Dell EMC Data Protection Search

How to mitigate CVE-2019-3689

Install updates from vendor's website.

Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
RSA Authentication Manager - update to 8.4 Patch 9
Dell EMC Data Protection Search - update to 19.3.0

External References

Related Security Bulletins