CVE-2019-3690
05.12.2019, 16:15
The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control over a path that is traversed by chkstat to escalate privileges.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| opensuse | leap | 15.1 |
𝑥
= Vulnerable software versions
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| permissions-20181116 |
| ||||||||||||||||||
| permissions-20181224 |
| ||||||||||||||||||
| permissions-20201225 |
| ||||||||||||||||||
| permissions-20240826 |
| ||||||||||||||||||
| permissions-zypp-plugin-20181116 |
| ||||||||||||||||||
| permissions-zypp-plugin-20181224 |
| ||||||||||||||||||
| permissions-zypp-plugin-20201225 |
| ||||||||||||||||||
| permissions-zypp-plugin-20240826 |
|