Permissions, Privileges, and Access Controls in SUSE Linux - CVE-2019-3689
Published: October 29, 2019
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure permissions on the " /var/lib/nfs" directory owned by statd:nogroup in the nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.
Successful exploitation of the vulnerability may allow a local user to escalate privileges on the system.
Affected software
Opensuse
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
RSA Authentication Manager
Dell EMC Data Protection Search
How to mitigate CVE-2019-3689
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
RSA Authentication Manager - update to 8.4 Patch 9
Dell EMC Data Protection Search - update to 19.3.0