← Back

CVE-2019-3699

nvd nist
Published: Jan 24, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE Factory privoxy version 3.0.28-2.1 and prior versions.

Affected (2)

Products: Privoxy: Privoxy
1 product
Privoxy
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.0.28-lp151.1.1
Running on/withPlatform Versions
Opensuse
Leap
Version 15.1
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.0.28-2.1
Running on/withPlatform Versions
Opensuse
Factory
All versions

References (2)

Source: meissner@suse.de
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.