CVE-2019-3461
published 2019-02-04CVE-2019-3461: Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via…
PriorityP431high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.25%
16.7th percentile
Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via rename() could potentially lead to a file being placed elsewhereon the filesystem hierarchy (e.g. /etc/cron.d/) if the directory being cleaned up was on the same physical filesystem. Fixed versions include 1.6.13+nmu1+deb9u1 and 1.6.14.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tmpreaper | < tmpreaper 1.6.14 (bookworm) | tmpreaper 1.6.14 (bookworm) |
| debian | tmpreaper | — | — |
| debian | tmpreaper | >= 0 < 1.6.14 | 1.6.14 |
| debian | tmpreaper | >= 0 < 1.6.14 | 1.6.14 |
| debian | tmpreaper | >= 0 < 1.6.14 | 1.6.14 |
| debian | tmpreaper | >= 0 < 1.6.14 | 1.6.14 |
| debian_gnu | linux_tmpreaper | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_debian7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qwp6-cgv8-84vv: Debian tmpreaper version 1
ghsa_unreviewed·2022-05-14
CVE-2019-3461 [HIGH] CWE-362 GHSA-qwp6-cgv8-84vv: Debian tmpreaper version 1
Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via rename() could potentially lead to a file being placed elsewhereon the filesystem hierarchy (e.g. /etc/cron.d/) if the directory being cleaned up was on the same physical filesystem. Fixed versions include 1.6.13+nmu1+deb9u1 and 1.6.14.
OSV
CVE-2019-3461: Debian tmpreaper version 1
osv·2019-02-04·CVSS 7.0
CVE-2019-3461 [HIGH] CVE-2019-3461: Debian tmpreaper version 1
Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via rename() could potentially lead to a file being placed elsewhereon the filesystem hierarchy (e.g. /etc/cron.d/) if the directory being cleaned up was on the same physical filesystem. Fixed versions include 1.6.13+nmu1+deb9u1 and 1.6.14.
Ubuntu
tmpreaper vulnerability
vendor_ubuntu·2019-07-29
CVE-2019-3461 tmpreaper vulnerability
Title: tmpreaper vulnerability
Summary: tmpreaper could be made to overwrite files as the administrator.
It was discovered that tmpreaper incorrectly handled certain mount operations. A
local attacker could possibly use this issue to create arbitrary files, leading
to privilege escalation.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-3461: tmpreaper - Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mo...
vendor_debian·2019·CVSS 7.0
CVE-2019-3461 [HIGH] CVE-2019-3461: tmpreaper - Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mo...
Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via rename() could potentially lead to a file being placed elsewhereon the filesystem hierarchy (e.g. /etc/cron.d/) if the directory being cleaned up was on the same physical filesystem. Fixed versions include 1.6.13+nmu1+deb9u1 and 1.6.14.
Scope: local
bookworm: resolved (fixed in 1.6.14)
bullseye: resolved (fixed in 1.6.14)
forky: resolved (fixed in 1.6.14)
sid: resolved (fixed in 1.6.14)
trixie: resolved (fixed in 1.6.14)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=918956https://lists.debian.org/debian-lts-announce/2019/01/msg00017.htmlhttps://lists.debian.org/debian-security-announce/2019/msg00003.htmlhttps://usn.ubuntu.com/4077-1/https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=918956https://lists.debian.org/debian-lts-announce/2019/01/msg00017.htmlhttps://lists.debian.org/debian-security-announce/2019/msg00003.htmlhttps://usn.ubuntu.com/4077-1/
2019-02-04
Published