CVE-2019-3698
CVSS 5.7 - MEDIUM
Description
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11 nagios version 3.0.6-1.25.36.3.1 and prior versions. openSUSE Factory nagios version 4.4.5-2.1 and prior versions.
Affected Products
6| Vendor | Product | Version |
|---|---|---|
| nagios | nagios |
All versions
|
| suse | linux_enterprise_server |
12
|
| nagios | nagios |
All versions
|
| suse | linux_enterprise_server |
11
|
| opensuse | backports_sle |
15.0
|
| opensuse | leap |
15.1
|
References
Weakness Types
CWE-59
CWE-59
CVE Information
- CVE ID:
CVE-2019-3698- Published:
- 2020-02-28
- Modified:
- 2024-11-21
- CVSS Score:
- 5.7
- Severity:
- MEDIUM
- Vector:
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
Affected Vendors
suse
opensuse
nagios
Quick Actions
CVSS Severity Scale
0.0 - 3.9
LOW
4.0 - 6.9
MEDIUM
7.0 - 8.9
HIGH
9.0 - 10.0
CRITICAL