CVE-2019-3687
Last modified
CVE-2019-3687 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to 081d081dcfaf61710bda34bc21c80c66276119aa.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to 081d081dcfaf61710bda34bc21c80c66276119aa.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Suse | Linux Enterprise Server | All versions |
References
- https://bugzilla.suse.com/show_bug.cgi?id=1148788Issue Tracking, Vendor Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1148788Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3687?
How severe is CVE-2019-3687?
How do I fix CVE-2019-3687?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-3681A External Control of File Name or Path vulnerability in osc…9.8
- CVE-2019-3682The docker-kubic package in SUSE CaaS Platform 3.0 before 17…7.8
- CVE-2019-3683The keystone-json-assignment package in SUSE Openstack Cloud…8.8
- CVE-2019-3684SUSE Manager until version 4.0.7 and Uyuni until commit 1b42…5.9
- CVE-2019-3685Open Build Service before version 0.165.4 diddn't validate T…7.7
- CVE-2019-3686openQA before commit c172e8883d8f32fced5e02f9b6faaacc913df27…6.1
- CVE-2019-3688The /usr/sbin/pinger binary packaged with squid in SUSE Linu…7.1
- CVE-2019-3689The nfs-utils package in SUSE Linux Enterprise Server 12 bef…9.8
- CVE-2019-3690The chkstat tool in the permissions package followed symlink…7.8
- CVE-2019-3691A Symbolic Link (Symlink) Following vulnerability in the pac…7.8
- CVE-2019-3692The packaging of inn on SUSE Linux Enterprise Server 11; ope…7.8
- CVE-2019-3693A symlink following vulnerability in the packaging of mailma…7.8
Are you affected by CVE-2019-3687?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
