CVE-2019-3689
published 2019-09-19CVE-2019-3689: The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.52%
71.7th percentile
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nfs-utils | < nfs-utils 1:1.3.4-3 (bookworm) | nfs-utils 1:1.3.4-3 (bookworm) |
| linux-nfs | nfs-utils | <= 1.3.0-34.18.1 | — |
| linux-nfs | nfs-utils | <= 2.1.1-6.10.2 | — |
| linux-nfs | nfs-utils | >= 0 < 1:1.3.4-3 | 1:1.3.4-3 |
| linux-nfs | nfs-utils | >= 0 < 1:1.3.4-3 | 1:1.3.4-3 |
| linux-nfs | nfs-utils | >= 0 < 1:1.3.4-3 | 1:1.3.4-3 |
| linux-nfs | nfs-utils | >= 0 < 1:1.3.4-3 | 1:1.3.4-3 |
| suse | suse_linux_enterprise_server_12 | — | — |
| suse | suse_linux_enterprise_server_15 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
nfs-utils vulnerability
vendor_ubuntu·2020-06-22
CVE-2019-3689 nfs-utils vulnerability
Title: nfs-utils vulnerability
Summary: nfs-utils could be made to overwrite files as the administrator.
It was discovered that the nfs-utils package set incorrect permissions on
the /var/lib/nfs directory. An attacker could possibly use this issue to
escalate privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nfs-utils: root-owned files stored in insecure /var/lib/nfs
vendor_redhat·2019-09-17·CVSS 5.1
CVE-2019-3689 [MEDIUM] CWE-276 nfs-utils: root-owned files stored in insecure /var/lib/nfs
nfs-utils: root-owned files stored in insecure /var/lib/nfs
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.
Statement: This issue did not affect the versions of nfs-utils as shipped with Red Hat Enterprise Linux 6, 7, and 8 as /var/lib/nfs directory is owned by root:root.
Package: nfs-utils (Red Hat Enterprise Linux 5) - Out of support scope
Package: nfs-utils (Red Hat Enterprise Linux 6) - Not affected
P
Debian
CVE-2019-3689: nfs-utils - The nfs-utils package in SUSE Linux Enterprise Server 12 before and including ve...
vendor_debian·2019·CVSS 5.1
CVE-2019-3689 [MEDIUM] CVE-2019-3689: nfs-utils - The nfs-utils package in SUSE Linux Enterprise Server 12 before and including ve...
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.
Scope: local
bookworm: resolved (fixed in 1:1.3.4-3)
bullseye: resolved (fixed in 1:1.3.4-3)
forky: resolved (fixed in 1:1.3.4-3)
sid: resolved (fixed in 1:1.3.4-3)
trixie: resolved (fixed in 1:1.3.4-3)
GHSA
GHSA-qh2q-m44h-cfm8: The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1
ghsa_unreviewed·2022-05-24
CVE-2019-3689 [HIGH] CWE-276 GHSA-qh2q-m44h-cfm8: The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system if fs.protected_symlinks is not set
OSV
CVE-2019-3689: The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1
osv·2019-09-19·CVSS 9.8
CVE-2019-3689 [CRITICAL] CVE-2019-3689: The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3689 nfs-utils: root-owned files stored in insecure /var/lib/nfs [fedora-all]
bugzilla·2020-06-23·CVSS 5.1
CVE-2019-3689 [MEDIUM] CVE-2019-3689 nfs-utils: root-owned files stored in insecure /var/lib/nfs [fedora-all]
CVE-2019-3689 nfs-utils: root-owned files stored in insecure /var/lib/nfs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2019-3689 nfs-utils: root-owned files stored in insecure /var/lib/nfs
bugzilla·2020-06-23·CVSS 5.1
CVE-2019-3689 [MEDIUM] CVE-2019-3689 nfs-utils: root-owned files stored in insecure /var/lib/nfs
CVE-2019-3689 nfs-utils: root-owned files stored in insecure /var/lib/nfs
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.
Reference:
https://bugzilla.suse.com/show_bug.cgi?id=1150733
Upstream commit:
https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commitdiff;h=fee2cc29e888f2ced6a76990923aef19d326dc0e
Discussion:
Created nfs-utils tracking bugs for this issue:
Affects: fedora-all [bug 1850196]
---
S
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00071.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00006.htmlhttps://bugzilla.suse.com/show_bug.cgi?id=1150733https://git.linux-nfs.org/?p=steved/nfs-utils.git%3Ba=commitdiff%3Bh=fee2cc29e888f2ced6a76990923aef19d326dc0ehttps://lists.debian.org/debian-lts-announce/2019/10/msg00026.htmlhttps://usn.ubuntu.com/4400-1/http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00071.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00006.htmlhttps://bugzilla.suse.com/show_bug.cgi?id=1150733https://git.linux-nfs.org/?p=steved/nfs-utils.git%3Ba=commitdiff%3Bh=fee2cc29e888f2ced6a76990923aef19d326dc0ehttps://lists.debian.org/debian-lts-announce/2019/10/msg00026.htmlhttps://usn.ubuntu.com/4400-1/
2019-09-19
Published