Vulnerability Description
The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to 081d081dcfaf61710bda34bc21c80c66276119aa.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Suse | Linux Enterprise Server | - |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00010.html
- https://bugzilla.suse.com/show_bug.cgi?id=1148788Issue TrackingVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00010.html
- https://bugzilla.suse.com/show_bug.cgi?id=1148788Issue TrackingVendor Advisory
FAQ
What is CVE-2019-3687?
CVE-2019-3687 is a vulnerability with a CVSS score of 4.0 (MEDIUM). The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Serv...
How severe is CVE-2019-3687?
CVE-2019-3687 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-3687?
Check the references section above for vendor advisories and patch information. Affected products include: Suse Linux Enterprise Server.