CVE-2019-19041
Last modified
CVE-2019-19041 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An issue was discovered in Xorux Lpar2RRD 6.11 and Stor2RRD 2.61, as distributed in Xorux 2.41. They do not correctly verify the integrity of an upgrade package before processing it. EPSS estimates a 2.01% chance of exploitation in the next 30 days.
Description
An issue was discovered in Xorux Lpar2RRD 6.11 and Stor2RRD 2.61, as distributed in Xorux 2.41. They do not correctly verify the integrity of an upgrade package before processing it. As a result, official upgrade packages can be modified to inject an arbitrary Bash script that will be executed by the underlying system. It is possible to achieve this by modifying the values in the files.SUM file (which are used for integrity control) and injecting malicious code into the upgrade.sh file.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xorur | Lpar2rrd | 6.11 |
| Xorur | Stor2rrd | 2.61 |
References
- https://github.com/gotenigatien/Xorux-critical-vulnerability/blob/master/README.mdExploit, Patch, Third Party Advisory
- https://github.com/gotenigatien/Xorux-critical-vulnerability/blob/master/README.mdExploit, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-19041?
How severe is CVE-2019-19041?
How do I fix CVE-2019-19041?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-19035jhead 3.03 is affected by: heap-based buffer over-read. The …5.5
- CVE-2019-19036btrfs_root_node in fs/btrfs/ctree.c in the Linux kernel thro…5.5
- CVE-2019-19037ext4_empty_dir in fs/ext4/namei.c in the Linux kernel throug…5.5
- CVE-2019-19039__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux k…5.5
- CVE-2019-1904A vulnerability in the web-based UI (web UI) of Cisco IOS XE…8.8
- CVE-2019-19040KairosDB through 1.2.2 has XSS in view.html because of showE…6.1
- CVE-2019-19043A memory leak in the i40e_setup_macvlans() function in drive…5.5
- CVE-2019-19044Two memory leaks in the v3d_submit_cl_ioctl() function in dr…7.5
- CVE-2019-19045A memory leak in the mlx5_fpga_conn_create_cq() function in …4.4
- CVE-2019-19046A memory leak in the __ipmi_bmc_register() function in drive…6.5
- CVE-2019-19047A memory leak in the mlx5_fw_fatal_reporter_dump() function …5.5
- CVE-2019-19048A memory leak in the crypto_reportstat() function in drivers…7.5
Are you affected by CVE-2019-19041?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
