PT-2020-10009 · Suse+1 · Suse Linux Enterprise Server 15+3
Matthias Gerstner
·
Published
2020-02-26
·
Updated
2024-06-15
·
CVE-2019-18901
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
mariadb versions prior to 10.2.31-3.25.1 on SUSE Linux Enterprise Server 12
mariadb versions prior to 10.2.31-3.26.1 on SUSE Linux Enterprise Server 15
Description
A UNIX Symbolic Link (Symlink) Following issue in the mysql-systemd-helper of the mariadb packaging allows local attackers to change the permissions of arbitrary files to 0640.
Recommendations
For mariadb versions prior to 10.2.31-3.25.1 on SUSE Linux Enterprise Server 12, update to version 10.2.31-3.25.1 or later.
For mariadb versions prior to 10.2.31-3.26.1 on SUSE Linux Enterprise Server 15, update to version 10.2.31-3.26.1 or later.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse Linux Enterprise Server 12
Suse Linux Enterprise Server 15
Suse
Mariadb