CVE-2019-3695
published 2020-03-03CVE-2019-3695: A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.47%
38.0th percentile
A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows the user pcp to run code as root by placing it into /var/log/pcp/configs.sh This issue affects: SUSE Linux Enterprise High Performance Computing 15-ESPOS pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise High Performance Computing 15-LTSS pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Module for Development Tools 15 pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Module for Development Tools 15-SP1 pcp versions prior to 4.3.1-3.5.3. SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Server 15-LTSS pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Server for SAP 15 pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Software Development Kit 12-SP4 pcp versions prior to 3.11.9-6.14.1. SUSE Linux Enterprise Software Development Kit 12-SP5 pcp versions prior to 3.11.9-6.14.1. openSUSE Leap 15.1 pcp versions prior to 4.3.1-lp151.2.3.1.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | opensuse_leap_15.1 | >= pcp < 4.3.1-lp151.2.3.1 | 4.3.1-lp151.2.3.1 |
| opensuse | pcp | < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| opensuse | pcp | < 4.3.1-3.5.3 | 4.3.1-3.5.3 |
| opensuse | pcp | < 3.11.9-6.14.1 | 3.11.9-6.14.1 |
| opensuse | pcp | < 4.3.1-lp151.2.3.1 | 4.3.1-lp151.2.3.1 |
| suse | suse_linux_enterprise_high_performance_computing_15-espos | >= pcp < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| suse | suse_linux_enterprise_high_performance_computing_15-ltss | >= pcp < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| suse | suse_linux_enterprise_module_for_development_tools_15 | >= pcp < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| suse | suse_linux_enterprise_module_for_development_tools_15-sp1 | >= pcp < 4.3.1-3.5.3 | 4.3.1-3.5.3 |
| suse | suse_linux_enterprise_module_for_open_buildservice_development_tools_15 | >= pcp < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| suse | suse_linux_enterprise_server_15-ltss | >= pcp < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| suse | suse_linux_enterprise_server_for_sap_15 | >= pcp < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| suse | suse_linux_enterprise_software_development_kit_12-sp4 | >= pcp < 3.11.9-6.14.1 | 3.11.9-6.14.1 |
| suse | suse_linux_enterprise_software_development_kit_12-sp5 | >= pcp < 3.11.9-6.14.1 | 3.11.9-6.14.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3g68-p942-4533: A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linu
ghsa_unreviewed·2022-05-24
CVE-2019-3695 [HIGH] GHSA-3g68-p942-4533: A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linu
A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows the user pcp to run code as root by placing it into /var/log/pcp/configs.sh This issue affects: SUSE Linux Enterprise High Performance Computing 15-ESPOS pcp versions prior to 3.11.9-5.8.1. SUSE Linu
Red Hat
pcp: Local privilege escalation in pcp spec file %post section
vendor_redhat·2019-10-14·CVSS 8.4
CVE-2019-3695 [HIGH] CWE-94 pcp: Local privilege escalation in pcp spec file %post section
pcp: Local privilege escalation in pcp spec file %post section
A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows the user pcp to run code as root by placing it into /var/log/pcp/configs.sh This issue affects: SUSE Linux Enterprise High Performance
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3695 pcp: Local privilege escalation in pcp spec file %post section [fedora-all]
bugzilla·2020-03-09·CVSS 8.4
CVE-2019-3695 [HIGH] CVE-2019-3695 pcp: Local privilege escalation in pcp spec file %post section [fedora-all]
CVE-2019-3695 pcp: Local privilege escalation in pcp spec file %post section [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2019-3695 pcp: Local privilege escalation in pcp spec file %post section
bugzilla·2020-03-09·CVSS 8.4
CVE-2019-3695 [HIGH] CVE-2019-3695 pcp: Local privilege escalation in pcp spec file %post section
CVE-2019-3695 pcp: Local privilege escalation in pcp spec file %post section
A Improper Control of Generation of Code vulnerability in the rpm packaging of pcp allows the user pcp to run code as root by placing it into /var/log/pcp/configs.sh.
References:
https://bugzilla.suse.com/show_bug.cgi?id=1152763
Discussion:
Created pcp tracking bugs for this issue:
Affects: fedora-all [bug 1811704]
---
This issue was resolved some time ago by removing compatibility code in PCP v5 - all current Fedora versions are unaffected by the issue.
commit 34c83f7ee46224fe410572f33c57a739f7bd044f
Author: Nathan Scott
Date: Sun Oct 6 14:10:40 2019 +1100
build: drop old config file transition code from rpm specs
Its been many years since this transition was done, good time
now with pcp-5.0.0 to full
2020-03-03
Published