CVE-2019-3698

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11 nagios version 3.0.6-1.25.36.3.1 and prior versions. openSUSE Factory nagios version 4.4.5-2.1 and prior versions.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.7 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
nagiosnagios
𝑥
< 3.5.1
nagiosnagios
𝑥
< 3.0.6
opensusebackports_sle
15.0:sp1
opensuseleap
15.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
icinga
bionic
not-affected
eoan
not-affected
trusty
dne
xenial
not-affected
nagios3
bionic
not-affected
eoan
dne
trusty
dne
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
sysuser-shadow
suse enterprise server 12 SP3
2.0-1.9.1
fixed
suse enterprise server 12 SP5
2.0-1.9.1
fixed
sysuser-tools
suse enterprise server 12 SP3
2.0-1.9.1
fixed
suse enterprise server 12 SP5
2.0-1.9.1
fixed