Bug 1803200 (CVE-2019-3699) - CVE-2019-3699 privoxy: local privilege escalation from privoxy to root
Summary: CVE-2019-3699 privoxy: local privilege escalation from privoxy to root
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2019-3699
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1803201
TreeView+ depends on / blocked
 
Reported: 2020-02-14 16:38 UTC by Guilherme de Almeida Suckevicz
Modified: 2020-02-24 02:12 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2020-02-14 16:55:59 UTC
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2020-02-14 16:38:53 UTC
UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE Factory privoxy version 3.0.28-2.1 and prior versions.

Reference:
https://bugzilla.suse.com/show_bug.cgi?id=1157449

Comment 1 Gwyn Ciesla 2020-02-14 16:55:59 UTC
This appears to be SUSE-only, and does not impact Fedora. Please reopen if this is not the case, with details.


Note You need to log in before you can comment on or make changes to this bug.