Description
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1965-1 | nfs-utils security update |
EUVD |
EUVD-2019-13324 | The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system. |
Ubuntu USN |
USN-4400-1 | nfs-utils vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2024-09-17T04:14:20.947Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3689
No data.
Status : Modified
Published: 2019-09-19T14:15:10.650
Modified: 2024-11-21T04:42:20.263
Link: CVE-2019-3689
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN