PT-2020-2767 · Suse+3 · Suse Linux Enterprise High Performance Computing 15-Ltss+13
Johannes Segitz
·
Published
2019-10-14
·
Updated
2024-06-15
·
CVE-2019-3695
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SUSE Linux Enterprise High Performance Computing 15-ESPOS pcp versions prior to 3.11.9-5.8.1
SUSE Linux Enterprise High Performance Computing 15-LTSS pcp versions prior to 3.11.9-5.8.1
SUSE Linux Enterprise Module for Development Tools 15 pcp versions prior to 3.11.9-5.8.1
SUSE Linux Enterprise Module for Development Tools 15-SP1 pcp versions prior to 4.3.1-3.5.3
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 pcp versions prior to 3.11.9-5.8.1
SUSE Linux Enterprise Server 15-LTSS pcp versions prior to 3.11.9-5.8.1
SUSE Linux Enterprise Server for SAP 15 pcp versions prior to 3.11.9-5.8.1
SUSE Linux Enterprise Software Development Kit 12-SP4 pcp versions prior to 3.11.9-6.14.1
SUSE Linux Enterprise Software Development Kit 12-SP5 pcp versions prior to 3.11.9-6.14.1
openSUSE Leap 15.1 pcp versions prior to 4.3.1-lp151.2.3.1
Description
The issue is related to an Improper Control of Generation of Code vulnerability in the packaging of pcp, allowing a user to run code as root by placing it into /var/log/pcp/configs.sh. This vulnerability can be exploited to execute arbitrary code.
Recommendations
For SUSE Linux Enterprise High Performance Computing 15-ESPOS pcp versions prior to 3.11.9-5.8.1, update to version 3.11.9-5.8.1 or later.
For SUSE Linux Enterprise High Performance Computing 15-LTSS pcp versions prior to 3.11.9-5.8.1, update to version 3.11.9-5.8.1 or later.
For SUSE Linux Enterprise Module for Development Tools 15 pcp versions prior to 3.11.9-5.8.1, update to version 3.11.9-5.8.1 or later.
For SUSE Linux Enterprise Module for Development Tools 15-SP1 pcp versions prior to 4.3.1-3.5.3, update to version 4.3.1-3.5.3 or later.
For SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 pcp versions prior to 3.11.9-5.8.1, update to version 3.11.9-5.8.1 or later.
For SUSE Linux Enterprise Server 15-LTSS pcp versions prior to 3.11.9-5.8.1, update to version 3.11.9-5.8.1 or later.
For SUSE Linux Enterprise Server for SAP 15 pcp versions prior to 3.11.9-5.8.1, update to version 3.11.9-5.8.1 or later.
For SUSE Linux Enterprise Software Development Kit 12-SP4 pcp versions prior to 3.11.9-6.14.1, update to version 3.11.9-6.14.1 or later.
For SUSE Linux Enterprise Software Development Kit 12-SP5 pcp versions prior to 3.11.9-6.14.1, update to version 3.11.9-6.14.1 or later.
For openSUSE Leap 15.1 pcp versions prior to 4.3.1-lp151.2.3.1, update to version 4.3.1-lp151.2.3.1 or later.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Red Hat
Suse Linux Enterprise High Performance Computing 15-Espos
Suse Linux Enterprise High Performance Computing 15-Ltss
Suse Linux Enterprise Module For Development Tools 15
Suse Linux Enterprise Module For Development Tools 15-Sp1
Suse Linux Enterprise Module For Open Buildservice Development Tools 15
Suse Linux Enterprise Server 15
Suse Linux Enterprise Server For Sap 15
Suse Linux Enterprise Software Development Kit 12-Sp4
Suse Linux Enterprise Software Development Kit 12-Sp5
Suse
Opensuse Leap 15.1
Pcp