Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2019-3689

Published: 19 September 2019

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.

Priority

Low

Cvss 3 Severity Score

9.8

Score breakdown

Status

Package Release Status
nfs-utils
Launchpad, Ubuntu, Debian
bionic
Released (1:1.3.4-2.1ubuntu5.3)
disco Ignored
(end of life)
eoan
Released (1:1.3.4-2.5ubuntu2.1)
focal
Released (1:1.3.4-2.5ubuntu3.3)
groovy
Released (1:1.3.4-2.5ubuntu5)
hirsute
Released (1:1.3.4-2.5ubuntu5)
impish
Released (1:1.3.4-2.5ubuntu5)
jammy
Released (1:1.3.4-2.5ubuntu5)
kinetic
Released (1:1.3.4-2.5ubuntu5)
lunar
Released (1:1.3.4-2.5ubuntu5)
mantic
Released (1:1.3.4-2.5ubuntu5)
trusty Needed

upstream
Released (1:1.3.4-3)
xenial
Released (1:1.2.8-9ubuntu12.3)
Patches:
upstream: https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commitdiff;h=fee2cc29e888f2ced6a76990923aef19d326dc0e
vendor: https://salsa.debian.org/debian/nfs-utils/-/commit/5eb61fb20053ed69a7396d44928e5bc66d86ef43
vendor: https://salsa.debian.org/debian/nfs-utils/-/commit/e63eb85dd956dce5df1f112e01a421c1cc8b3483

Severity score breakdown

Parameter Value
Base score 9.8
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H