Lucene search

K
cveSuseCVE-2019-3691
HistoryJan 23, 2020 - 4:15 p.m.

CVE-2019-3691

2020-01-2316:15:11
CWE-59
suse
web.nvd.nist.gov
94
cve-2019-3691
symlink
packaging
suse linux enterprise server
opensuse factory
privilege escalation
nvd
vulnerability

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

5.1%

A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects: SUSE Linux Enterprise Server 15 munge versions prior to 0.5.13-4.3.1. openSUSE Factory munge versions prior to 0.5.13-6.1.

Affected configurations

Nvd
Node
opensusemungeRange<0.5.13-4.3.1
AND
susesuse_linux_enterprise_serverMatch15
Node
opensusemungeRange<0.5.13-6.1
AND
opensusefactoryMatch-
VendorProductVersionCPE
opensusemunge*cpe:2.3:a:opensuse:munge:*:*:*:*:*:*:*:*
susesuse_linux_enterprise_server15cpe:2.3:o:suse:suse_linux_enterprise_server:15:*:*:*:*:*:*:*
opensusefactory-cpe:2.3:a:opensuse:factory:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "SUSE Linux Enterprise Server 15",
    "vendor": "SUSE",
    "versions": [
      {
        "lessThan": "0.5.13-4.3.1",
        "status": "affected",
        "version": "munge",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Factory",
    "vendor": "openSUSE",
    "versions": [
      {
        "lessThan": "0.5.13-6.1",
        "status": "affected",
        "version": "munge",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

5.1%