PT-2020-10913 · Opensuse · Munin

Johannes Segitz

·

Published

2020-01-24

·

Updated

2022-11-10

·

CVE-2019-3694

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openSUSE Factory munin versions 2.0.49-4.2 and prior versions openSUSE Leap 15.1 munin versions 2.0.40-lp151.1.1 and prior versions
Description A Symbolic Link (Symlink) Following issue in the packaging of munin allows local attackers to escalate from user munin to root.
Recommendations For openSUSE Factory munin versions 2.0.49-4.2 and prior versions, update to a version later than 2.0.49-4.2 to resolve the issue. For openSUSE Leap 15.1 munin versions 2.0.40-lp151.1.1 and prior versions, update to a version later than 2.0.40-lp151.1.1 to resolve the issue.

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2019-3694

Affected Products

Munin