CVE-2019-5259
published 2019-12-16CVE-2019-5259: There is an information leakage vulnerability on some Huawei products(AR120-S;AR1200;AR1200-S;AR150;AR150-S;AR160;AR200;AR200-S;AR2200;AR2200-S;AR3200;AR3600)…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.56%
43.1th percentile
There is an information leakage vulnerability on some Huawei products(AR120-S;AR1200;AR1200-S;AR150;AR150-S;AR160;AR200;AR200-S;AR2200;AR2200-S;AR3200;AR3600). An attacker with low permissions can view some high-privilege information by running specific commands.Successful exploit could cause an information disclosure condition.
Affected
73 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cron_project | cron | >= 0 < 3.0pl1-128.1ubuntu1.1 | 3.0pl1-128.1ubuntu1.1 |
| cron_project | cron | >= 0 < 3.0pl1-128.1ubuntu1.2 | 3.0pl1-128.1ubuntu1.2 |
| cron_project | cron | >= 0 < 3.0pl1-128ubuntu2+esm2 | 3.0pl1-128ubuntu2+esm2 |
| huawei | ar120-s_firmware | — | — |
| huawei | ar120-s_firmware | — | — |
| huawei | ar120-s_firmware | — | — |
| huawei | ar120-s_firmware | — | — |
| huawei | ar120-s_firmware | — | — |
| huawei | ar120-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar150-s_firmware | — | — |
| huawei | ar150-s_firmware | — | — |
| huawei | ar150-s_firmware | — | — |
| huawei | ar150-s_firmware | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g3x5-hj34-q968: There is an information leakage vulnerability on some Huawei products(AR120-S;AR1200;AR1200-S;AR150;AR150-S;AR160;AR200;AR200-S;AR2200;AR2200-S;AR3200
ghsa_unreviewed·2022-05-24
CVE-2019-5259 [MEDIUM] GHSA-g3x5-hj34-q968: There is an information leakage vulnerability on some Huawei products(AR120-S;AR1200;AR1200-S;AR150;AR150-S;AR160;AR200;AR200-S;AR2200;AR2200-S;AR3200
There is an information leakage vulnerability on some Huawei products(AR120-S;AR1200;AR1200-S;AR150;AR150-S;AR160;AR200;AR200-S;AR2200;AR2200-S;AR3200;AR3600). An attacker with low permissions can view some high-privilege information by running specific commands.Successful exploit could cause an information disclosure condition.
OSV
cron regression
osv·2022-05-11·CVSS 6.7
CVE-2017-9525 cron regression
cron regression
USN-5259-1 and USN-5259-2 fixed vulnerabilities in Cron. Unfortunately
that update was incomplete and could introduce a regression. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the postinst maintainer script in Cron unsafely
handled file permissions during package install or update operations.
An attacker could possibly use this issue to perform a privilege
escalation attack. (CVE-2017-9525)
Florian Weimer discovered that Cron incorrectly handled certain memory
operations during crontab file creation. An attacker could possibly use
this issue to cause a denial of service. (CVE-2019-9704)
It was discovered that Cron incorrectly handled user input during crontab
file creation. An attacker could poss
OSV
cron vulnerabilities
osv·2022-05-06·CVSS 6.7
CVE-2017-9525 cron vulnerabilities
cron vulnerabilities
USN-5259-1 fixed several vulnerabilities in Cron. This update provides
the corresponding update for Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that the postinst maintainer script in Cron unsafely
handled file permissions during package install or update operations.
An attacker could possibly use this issue to perform a privilege
escalation attack. (CVE-2017-9525)
Florian Weimer discovered that Cron incorrectly handled certain memory
operations during crontab file creation. An attacker could possibly use
this issue to cause a denial of service. (CVE-2019-9704)
It was discovered that Cron incorrectly handled user input during crontab
file creation. An attacker could possibly use this issue to cause a denial
of service. (CVE-2019-9705)
It was dis
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-12-16
Published