Vulnerability Details CVE-2019-3692
The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE Linux Enterprise Server 11 inn version 2.4.2-170.21.3.1 and prior versions. openSUSE Factory inn version 2.6.2-2.2 and prior versions. openSUSE Leap 15.1 inn version 2.5.4-lp151.2.47 and prior versions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.4%
CVSS Severity
CVSS v3 Score 7.7
CVSS v2 Score 7.2
Products affected by CVE-2019-3692
-
cpe:2.3:a:opensuse:backports_sle:15.0
-
cpe:2.3:a:opensuse:factory:-
-
-
Suse
»
Inn
»
Version: 2.4.2-170.21.3.1
cpe:2.3:a:suse:inn:2.4.2-170.21.3.1
-
cpe:2.3:a:suse:inn:2.4.2-20.9.1
-
Suse
»
Inn
»
Version: 2.5.4-lp151.2.47
cpe:2.3:a:suse:inn:2.5.4-lp151.2.47
-
cpe:2.3:a:suse:inn:2.6.2-2.2
-
cpe:2.3:o:opensuse:leap:15.1
-
cpe:2.3:o:suse:linux_enterprise_server:11