"easy" permission profile allows everyone execute dumpcap and read all network traffic

CVE-2019-3687
4MEDIUM

Key Information

Vendor
Suse
Status
Suse Linux Enterprise Server
Vendor
CVE Published:
24 January 2020

Summary

The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to 081d081dcfaf61710bda34bc21c80c66276119aa.

Affected Version(s)

SUSE Linux Enterprise Server < 081d081dcfaf61710bda34bc21c80c66276119aa

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Risk change from: 3.3 to: 4 - (MEDIUM)

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Malte Kraus of SUSE
.