« Volver al listado

CVE-2019-3688

Estado: ModificadaAlta (7.1)—

The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by changing the binary

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-3688",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 9.2,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "meissner@suse.de",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.1,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "meissner@suse.de",
      "affectedData": [
        {
          "vendor": "SUSE",
          "product": "SUSE Linux Enterprise Server 15",
          "versions": [
            {
              "status": "affected",
              "version": "squid",
              "versionType": "custom",
              "lessThanOrEqual": "4.8-5.8.1"
            }
          ]
        },
        {
          "vendor": "SUSE",
          "product": "SUSE Linux Enterprise Server 12",
          "versions": [
            {
              "status": "affected",
              "version": "squid",
              "versionType": "custom",
              "lessThanOrEqual": "3.5.21-26.17.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-10-07T14:15:11.977",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.html",
      "source": "meissner@suse.de"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.html",
      "source": "meissner@suse.de"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00024.html",
      "source": "meissner@suse.de"
    },
    {
      "url": "https://bugzilla.suse.com/show_bug.cgi?id=1093414",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "meissner@suse.de"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00024.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.suse.com/show_bug.cgi?id=1093414",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "meissner@suse.de",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by changing the binary"
    },
    {
      "lang": "es",
      "value": "El binario /usr/sbin/pinger empaquetado con squid en SUSE Linux Enterprise Server 15 anterior e incluyendo la versión 4.8-5.8.1 y en SUSE Linux Enterprise Server 12 anterior e incluyendo la versión 3.5.21-26.17.1, presenta squid:root, permisos 0750 . Esto permitió a un atacante que comprometía al usuario squid conseguir persistencia al cambiar el binario."
    }
  ],
  "lastModified": "2026-06-17T02:35:23.057",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:suse:suse_linux_enterprise_server:12:sp1:*:*:ltss:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BF3B54D-9CE7-44A3-89FB-7747FADBD361"
            },
            {
              "criteria": "cpe:2.3:o:suse:suse_linux_enterprise_server:12:sp2:*:*:ltss:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F45BC40-F836-447D-A5B3-8A7FCF64A82E"
            },
            {
              "criteria": "cpe:2.3:o:suse:suse_linux_enterprise_server:12:sp3:*:*:ltss:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC4D0498-D6FB-4A73-B053-895AC60A4DEB"
            },
            {
              "criteria": "cpe:2.3:o:suse:suse_linux_enterprise_server:15:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "873082AA-2F7B-44C8-89D2-4DD48673BAE9"
            },
            {
              "criteria": "cpe:2.3:o:suse:suse_linux_enterprise_server:15:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7642C831-6063-4405-A352-431CE374458A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "meissner@suse.de"
}