CVE-2019-3698
Last modified
CVE-2019-3698 is a high-severity vulnerability rated 7/10 on the CVSS scale. UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11 nagios version 3.0.6-1.25.36.3.1 and prior versions. openSUSE Factory nagios version 4.4.5-2.1 and prior versions.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Nagios | Nagios | < 3.5.1 | — |
| Nagios | Nagios | < 3.0.6 | — |
| Opensuse | Backports Sle | 15.0 | Sp1 |
| Opensuse | Leap | 15.1 | — |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00014.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00022.htmlMailing List, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1156309Exploit, Issue Tracking, Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00014.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00022.htmlMailing List, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1156309Exploit, Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3698?
How severe is CVE-2019-3698?
How do I fix CVE-2019-3698?
Are you affected by CVE-2019-3698?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
