First published: Fri Jan 24 2020(Updated: )
UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE Factory privoxy version 3.0.28-2.1 and prior versions.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Privoxy | <3.0.28-lp151.1.1 | |
SUSE Linux | =15.1 | |
Privoxy | <3.0.28-2.1 | |
openSUSE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-3699.
CVE-2019-3699 has a severity score of 7.8 (high).
CVE-2019-3699 affects openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions, as well as openSUSE Factory privoxy version 3.0.28-2.1 and prior versions.
This vulnerability allows local attackers to escalate from user privoxy to root by exploiting a symbolic link (symlink) following vulnerability in the packaging of privoxy.
Yes, openSUSE Leap 15.1 is vulnerable to CVE-2019-3699 if privoxy version 3.0.28-lp151.1.1 or a prior version is used.