Vulnerability Description
lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ehang-Io | Nps | <= 0.23.2 |
Related Weaknesses (CWE)
References
- https://github.com/cnlh/nps/commit/7178b3380720e910d283036a8d39879a94105515PatchThird Party Advisory
- https://github.com/cnlh/nps/issues/176ExploitThird Party Advisory
- https://github.com/cnlh/nps/commit/7178b3380720e910d283036a8d39879a94105515PatchThird Party Advisory
- https://github.com/cnlh/nps/issues/176ExploitThird Party Advisory
FAQ
What is CVE-2019-15119?
CVE-2019-15119 is a vulnerability with a CVSS score of 5.5 (MEDIUM). lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.
How severe is CVE-2019-15119?
CVE-2019-15119 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15119?
Check the references section above for vendor advisories and patch information. Affected products include: Ehang-Io Nps.