PT-2019-13998 · Cnlh · Nps
Nico Waisman
+1
·
Published
2019-08-16
·
Updated
2025-04-23
·
CVE-2019-15119
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
cnlh nps versions 0.23.2 and earlier
Description
The issue arises from the use of 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps in lib/install/install.go, allowing a local user to overwrite files.
Recommendations
For versions 0.23.2 and earlier, consider changing the permissions of /usr/local/bin/nps and /usr/bin/nps to prevent file overwrites by local users. As a temporary workaround, restrict access to these files until a proper fix is applied.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nps