CVE-2019-3696
published 2020-03-03CVE-2019-3696: A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing…
PriorityP336high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.46%
36.9th percentile
A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local user pcp to overwrite arbitrary files with arbitrary content. This issue affects: SUSE Linux Enterprise High Performance Computing 15-ESPOS pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise High Performance Computing 15-LTSS pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Module for Development Tools 15 pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Module for Development Tools 15-SP1 pcp versions prior to 4.3.1-3.5.3. SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Server 15-LTSS pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Server for SAP 15 pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Software Development Kit 12-SP4 pcp versions prior to 3.11.9-6.14.1. SUSE Linux Enterprise Software Development Kit 12-SP5 pcp versions prior to 3.11.9-6.14.1. openSUSE Leap 15.1 pcp versions prior to 4.3.1-lp151.2.3.1.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | opensuse_leap_15.1 | >= pcp < 4.3.1-lp151.2.3.1 | 4.3.1-lp151.2.3.1 |
| opensuse | pcp | < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| opensuse | pcp | < 4.3.1-3.5.3 | 4.3.1-3.5.3 |
| opensuse | pcp | < 3.11.9-6.14.1 | 3.11.9-6.14.1 |
| opensuse | pcp | < 4.3.1-lp151.2.3.1 | 4.3.1-lp151.2.3.1 |
| seal-security | mongoose-fixed | >= 5.3.3 < 5.3.4 | 5.3.4 |
| suse | suse_linux_enterprise_high_performance_computing_15-espos | >= pcp < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| suse | suse_linux_enterprise_high_performance_computing_15-ltss | >= pcp < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| suse | suse_linux_enterprise_module_for_development_tools_15 | >= pcp < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| suse | suse_linux_enterprise_module_for_development_tools_15-sp1 | >= pcp < 4.3.1-3.5.3 | 4.3.1-3.5.3 |
| suse | suse_linux_enterprise_module_for_open_buildservice_development_tools_15 | >= pcp < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| suse | suse_linux_enterprise_server_15-ltss | >= pcp < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| suse | suse_linux_enterprise_server_for_sap_15 | >= pcp < 3.11.9-5.8.1 | 3.11.9-5.8.1 |
| suse | suse_linux_enterprise_software_development_kit_12-sp4 | >= pcp < 3.11.9-6.14.1 | 3.11.9-6.14.1 |
| suse | suse_linux_enterprise_software_development_kit_12-sp5 | >= pcp < 3.11.9-6.14.1 | 3.11.9-6.14.1 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
ghsa9.1CRITICAL
vendor_redhat8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Prototype Pollution in ali-security/mongoose
ghsa·2023-10-17·CVSS 9.1
CVE-2023-3696 [CRITICAL] CWE-1321 Prototype Pollution in ali-security/mongoose
Prototype Pollution in ali-security/mongoose
### Impact
This vulnerability causes a Prototype Pollution in document.js, through functions such as findByIdAndUpdate().
For applications using Express and EJS, this can potentially allow remote code execution.
### Patches
The original patched version for mongoose 5.3.3 did not include a fix for CVE-2023-3696. Therefore the existing version @seal-security/mongoose-fixed version 5.3.3 is affected by this vulnerability (though it is protected from CVE-2022-2564 and CVE-2019-17426). To mitigate this issue, a @seal-security/mongoose-fixed version 5.3.4 has been deployed. Note that this version is compatible with the original mongoose version 5.3.3, not version 5.3.4
### References
https://security.snyk.io/vuln/SNYK-JS-MONGOOSE-5777721
https://gi
GHSA
GHSA-crq2-xjm7-62p8: A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computin
ghsa_unreviewed·2022-05-24
CVE-2019-3696 [MEDIUM] GHSA-crq2-xjm7-62p8: A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computin
A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local user pcp to overwrite arbitrary files with arbitrary content. This issue affects: SUSE Linux Enterprise High Performance Computing 15-ESPOS pcp versions prior to 3.11.9-5.8
Red Hat
pcp: Local privilege escalation in pcp spec file through migrate_tempdirs
vendor_redhat·2019-10-14·CVSS 8.4
CVE-2019-3696 [HIGH] CWE-22 pcp: Local privilege escalation in pcp spec file through migrate_tempdirs
pcp: Local privilege escalation in pcp spec file through migrate_tempdirs
A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local user pcp to overwrite arbitrary files with arbitrary content. This issue affects: SUSE Linux Ente
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3696 pcp: Local privilege escalation in pcp spec file through migrate_tempdirs
bugzilla·2020-03-09·CVSS 8.4
CVE-2019-3696 [HIGH] CVE-2019-3696 pcp: Local privilege escalation in pcp spec file through migrate_tempdirs
CVE-2019-3696 pcp: Local privilege escalation in pcp spec file through migrate_tempdirs
A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the rpm packaging of pcp allows local user pcp to overwrite arbitrary files with arbitrary content.
References:
https://bugzilla.suse.com/show_bug.cgi?id=1153921
Discussion:
Created pcp tracking bugs for this issue:
Affects: fedora-all [bug 1811710]
---
This issue was resolved some time ago by removing compatibility code in PCP v5 - all current Fedora versions are unaffected by the issue.
commit 34c83f7ee46224fe410572f33c57a739f7bd044f
Author: Nathan Scott
Date: Sun Oct 6 14:10:40 2019 +1100
build: drop old config file transition code from rpm specs
Its been many years since this transition was done, good time
now
Bugzilla
CVE-2019-3696 pcp: Local privilege escalation in pcp spec file through migrate_tempdirs [fedora-all]
bugzilla·2020-03-09·CVSS 8.4
CVE-2019-3696 [HIGH] CVE-2019-3696 pcp: Local privilege escalation in pcp spec file through migrate_tempdirs [fedora-all]
CVE-2019-3696 pcp: Local privilege escalation in pcp spec file through migrate_tempdirs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
2020-03-03
Published