← back
CVE-2019-3690

chkstat follows untrusted symbolic links

CVSS 6.8 MEDIUMEPSS 0.4%CWE-59
The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control over a path that is traversed by chkstat to escalate privileges.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Affected products
SUSE · permissions

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →