CVE-2019-3844
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 4.5epss 0.9%
de la publicación al arma0 días
Publicada en NVD26 abr
1ª PoC26 abr
probabilidad de explotación
0.9%top 43% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the GID will be recycled.
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Productos afectados
[freedesktop.org] · systemdPoCs públicas encontradas — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/46760⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3844https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190619-0002/https://usn.ubuntu.com/4269-1/http://www.securityfocus.com/bid/108096