PT-2020-2767 · Suse+3 · Suse Linux Enterprise High Performance Computing 15-Ltss+13

Johannes Segitz

·

Published

2019-10-14

·

Updated

2024-06-15

·

CVE-2019-3695

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise High Performance Computing 15-ESPOS pcp versions prior to 3.11.9-5.8.1 SUSE Linux Enterprise High Performance Computing 15-LTSS pcp versions prior to 3.11.9-5.8.1 SUSE Linux Enterprise Module for Development Tools 15 pcp versions prior to 3.11.9-5.8.1 SUSE Linux Enterprise Module for Development Tools 15-SP1 pcp versions prior to 4.3.1-3.5.3 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 pcp versions prior to 3.11.9-5.8.1 SUSE Linux Enterprise Server 15-LTSS pcp versions prior to 3.11.9-5.8.1 SUSE Linux Enterprise Server for SAP 15 pcp versions prior to 3.11.9-5.8.1 SUSE Linux Enterprise Software Development Kit 12-SP4 pcp versions prior to 3.11.9-6.14.1 SUSE Linux Enterprise Software Development Kit 12-SP5 pcp versions prior to 3.11.9-6.14.1 openSUSE Leap 15.1 pcp versions prior to 4.3.1-lp151.2.3.1
Description The issue is related to an Improper Control of Generation of Code vulnerability in the packaging of pcp, allowing a user to run code as root by placing it into /var/log/pcp/configs.sh. This vulnerability can be exploited to execute arbitrary code.
Recommendations For SUSE Linux Enterprise High Performance Computing 15-ESPOS pcp versions prior to 3.11.9-5.8.1, update to version 3.11.9-5.8.1 or later. For SUSE Linux Enterprise High Performance Computing 15-LTSS pcp versions prior to 3.11.9-5.8.1, update to version 3.11.9-5.8.1 or later. For SUSE Linux Enterprise Module for Development Tools 15 pcp versions prior to 3.11.9-5.8.1, update to version 3.11.9-5.8.1 or later. For SUSE Linux Enterprise Module for Development Tools 15-SP1 pcp versions prior to 4.3.1-3.5.3, update to version 4.3.1-3.5.3 or later. For SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 pcp versions prior to 3.11.9-5.8.1, update to version 3.11.9-5.8.1 or later. For SUSE Linux Enterprise Server 15-LTSS pcp versions prior to 3.11.9-5.8.1, update to version 3.11.9-5.8.1 or later. For SUSE Linux Enterprise Server for SAP 15 pcp versions prior to 3.11.9-5.8.1, update to version 3.11.9-5.8.1 or later. For SUSE Linux Enterprise Software Development Kit 12-SP4 pcp versions prior to 3.11.9-6.14.1, update to version 3.11.9-6.14.1 or later. For SUSE Linux Enterprise Software Development Kit 12-SP5 pcp versions prior to 3.11.9-6.14.1, update to version 3.11.9-6.14.1 or later. For openSUSE Leap 15.1 pcp versions prior to 4.3.1-lp151.2.3.1, update to version 4.3.1-lp151.2.3.1 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02859
CESA-2020_3869
CVE-2019-3695
OPENSUSE-SU-2020:0213-1
OPENSUSE-SU-2020_0213-1
OPENSUSE-SU-2024:11152-1
RHSA-2020:3869
RHSA-2020_3869
SUSE-SU-2020:0355-1
SUSE-SU-2020:0356-1
SUSE-SU-2020:0357-1
SUSE-SU-2020_0355-1
SUSE-SU-2020_0356-1
SUSE-SU-2020_0357-1

Affected Products

Centos
Red Hat
Suse Linux Enterprise High Performance Computing 15-Espos
Suse Linux Enterprise High Performance Computing 15-Ltss
Suse Linux Enterprise Module For Development Tools 15
Suse Linux Enterprise Module For Development Tools 15-Sp1
Suse Linux Enterprise Module For Open Buildservice Development Tools 15
Suse Linux Enterprise Server 15
Suse Linux Enterprise Server For Sap 15
Suse Linux Enterprise Software Development Kit 12-Sp4
Suse Linux Enterprise Software Development Kit 12-Sp5
Suse
Opensuse Leap 15.1
Pcp