HIGH
squid: /usr/sbin/pinger packaged with wrong permission
Published Oct 7, 2019
7.1
HIGHCVSS 3.1
EPSS 0.34%
Description
The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by changing the binary
Affected products
-
- Version squidStatusaffectedConstraints<=3.5.21-26.17.1
- Version
-
- Version squidStatusaffectedConstraints<=4.8-5.8.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SUSE | SUSE Linux Enterprise Server 12 | n/a |
| ||||||
| SUSE | SUSE Linux Enterprise Server 15 | n/a |
|
OR
- 12
- 12
- 12
- 15
- 15
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00024.html vendor-advisoryx_refsource_SUSE
- https://bugzilla.suse.com/show_bug.cgi?id=1093414 x_refsource_CONFIRMIssue TrackingVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00024.html | vendor-advisoryx_refsource_SUSE | |
| https://bugzilla.suse.com/show_bug.cgi?id=1093414 | x_refsource_CONFIRMIssue TrackingVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner suse
Published Oct 7, 2019
Updated Sep 16, 2024
Reserved Jan 3, 2019
Link CVE-2019-3688
CISA Vulnrichment
Updated n/a