7.1

CVE-2019-3688

squid: /usr/sbin/pinger packaged with wrong permission

The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by changing the binary
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Suse ≫ Suse Linux Enterprise Server Version 12 Update sp1 SwEdition ltss
Suse ≫ Suse Linux Enterprise Server Version 12 Update sp2 SwEdition ltss
Suse ≫ Suse Linux Enterprise Server Version 12 Update sp3 SwEdition ltss
Suse ≫ Suse Linux Enterprise Server Version 15 Update -
Suse ≫ Suse Linux Enterprise Server Version 15 Update sp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.252
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
NIST 6.6 3.9 9.2
AV:L/AC:L/Au:N/C:N/I:C/A:C
SUSE 5.1 2.5 2.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.html
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.html
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00024.html
https://bugzilla.suse.com/show_bug.cgi?id=1093414
Vendor Advisory
Issue Tracking