CVE Database
/

CVE-2019-3690

Back to search

CVE-2019-3690

Published: Dec 5, 2019

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

6.8

MEDIUM

Description

The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control over a path that is traversed by chkstat to escalate privileges.

VendorProductVersions

SUSE

permissions

affected
unspecified - < a9e1d26cd49ef9ee0c2060c859321128a6dd4230

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

Low

Availability

None

References

openSUSE-SU-2019:2672
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now