CVE-2019-3690Link Following in Permissions

CWE-59Link Following2 documents2 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 72.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 5
Latest updateMay 24

Description

The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control over a path that is traversed by chkstat to escalate privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5suse/permissionsunspecifieda9e1d26cd49ef9ee0c2060c859321128a6dd4230
NVDopensuse/leap15.1

🔴Vulnerability Details

1
GHSA
GHSA-jxhx-2gqw-c77x: The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional2022-05-24
CVE-2019-3690 — Link Following in Suse Permissions | cvebase