CVE-2019-19585
Summary
| CVE | CVE-2019-19585 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-06 20:15:00 UTC |
| Updated | 2023-01-31 20:46:00 UTC |
| Description | An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apache configuration" update, apache has high privileges for some binaries. This can be exploited by an attacker to bypass local security restrictions. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| exploits-rconfig/rconfig_lpe.sh at master · v1k1ngfr/exploits-rconfig · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| raw.githubusercontent.com/v1k1ngfr/exploits/master/rconfig_lpe.sh | MISC | raw.githubusercontent.com | Exploit, Third Party Advisory |
| rConfig 3.9.4 searchField Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.