CVE-2019-3689
Summary
| CVE | CVE-2019-3689 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-19 14:15:00 UTC |
| Updated | 2023-11-07 03:10:00 UTC |
| Description | The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Linux-nfs | Nfs-utils | All | All | All | All |
| Application | Linux-nfs | Nfs-utils | All | All | All | All |
| Operating System | Suse | Linux Enterprise Server | 12 | All | All | All |
| Operating System | Suse | Linux Enterprise Server | 15 | All | All | All |
| Operating System | Suse | Linux Enterprise Server | 12 | All | All | All |
| Operating System | Suse | Linux Enterprise Server | 15 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.linux-nfs.org Git - steved/nfs-utils.git/commitdiff | MISC | git.linux-nfs.org | Third Party Advisory |
| git.linux-nfs.org Git - steved/nfs-utils.git/commitdiff | git.linux-nfs.org | ||
| USN-4400-1: nfs-utils vulnerability | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| [SECURITY] [DLA 1965-1] nfs-utils security update | MLIST | lists.debian.org | Third Party Advisory |
| [security-announce] openSUSE-SU-2019:2408-1: moderate: Security update f | SUSE | lists.opensuse.org | Vendor Advisory |
| [security-announce] openSUSE-SU-2019:2435-1: moderate: Security update f | SUSE | lists.opensuse.org | Vendor Advisory |
| Bug 1150733 – VUL-0: CVE-2019-3689: nfs-utils: root-owned files stored in insecure /var/lib/nfs | CONFIRM | bugzilla.suse.com | Issue Tracking, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Malte Kraus of SUSE