← Back

CVE-2019-3693

nvd nist
Published: Jan 24, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1 allowed local attackers to escalate their privileges from user wwwrun to root. Additionally arbitrary files could be changed to group mailman. This issue affects: SUSE Linux Enterprise Server 11 mailman versions prior to 2.1.15-9.6.15.1. SUSE Linux Enterprise Server 12 mailman versions prior to 2.1.17-3.11.1. openSUSE Leap 15.1 mailman version 2.1.29-lp151.2.14 and prior versions.

Affected (4)

1 product
Mailman
1 product
Backports Sle
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.1.15-9.6.15.1
Running on/withPlatform Versions
Suse
Linux Enterprise Server
Version 11
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.1.17-3.11.1
Running on/withPlatform Versions
Suse
Linux Enterprise Server
Version 12
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.1.29-lp151.2.14
Running on/withPlatform Versions
Opensuse
Leap
Version 15.1
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.0 sp1

References (6)

Source: meissner@suse.de
Mailing ListVendor Advisory
Source: meissner@suse.de
Mailing ListThird Party Advisory
Source: meissner@suse.de
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.