Rapid7 Vulnerability & Exploit Database

Amazon Linux AMI 2: CVE-2019-3695: Security patch for pcp (ALAS-2020-1561)

Back to Search

Amazon Linux AMI 2: CVE-2019-3695: Security patch for pcp (ALAS-2020-1561)

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
03/03/2020
Created
11/13/2020
Added
11/12/2020
Modified
11/12/2020

Description

A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows the user pcp to run code as root by placing it into /var/log/pcp/configs.sh This issue affects: SUSE Linux Enterprise High Performance Computing 15-ESPOS pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise High Performance Computing 15-LTSS pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Module for Development Tools 15 pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Module for Development Tools 15-SP1 pcp versions prior to 4.3.1-3.5.3. SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Server 15-LTSS pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Server for SAP 15 pcp versions prior to 3.11.9-5.8.1. SUSE Linux Enterprise Software Development Kit 12-SP4 pcp versions prior to 3.11.9-6.14.1. SUSE Linux Enterprise Software Development Kit 12-SP5 pcp versions prior to 3.11.9-6.14.1. openSUSE Leap 15.1 pcp versions prior to 4.3.1-lp151.2.3.1.

Solution(s)

  • amazon-linux-ami-2-upgrade-pcp
  • amazon-linux-ami-2-upgrade-pcp-conf
  • amazon-linux-ami-2-upgrade-pcp-debuginfo
  • amazon-linux-ami-2-upgrade-pcp-devel
  • amazon-linux-ami-2-upgrade-pcp-doc
  • amazon-linux-ami-2-upgrade-pcp-export-pcp2elasticsearch
  • amazon-linux-ami-2-upgrade-pcp-export-pcp2graphite
  • amazon-linux-ami-2-upgrade-pcp-export-pcp2influxdb
  • amazon-linux-ami-2-upgrade-pcp-export-pcp2json
  • amazon-linux-ami-2-upgrade-pcp-export-pcp2spark
  • amazon-linux-ami-2-upgrade-pcp-export-pcp2xml
  • amazon-linux-ami-2-upgrade-pcp-export-pcp2zabbix
  • amazon-linux-ami-2-upgrade-pcp-export-zabbix-agent
  • amazon-linux-ami-2-upgrade-pcp-gui
  • amazon-linux-ami-2-upgrade-pcp-import-collectl2pcp
  • amazon-linux-ami-2-upgrade-pcp-import-ganglia2pcp
  • amazon-linux-ami-2-upgrade-pcp-import-iostat2pcp
  • amazon-linux-ami-2-upgrade-pcp-import-mrtg2pcp
  • amazon-linux-ami-2-upgrade-pcp-import-sar2pcp
  • amazon-linux-ami-2-upgrade-pcp-libs
  • amazon-linux-ami-2-upgrade-pcp-libs-devel
  • amazon-linux-ami-2-upgrade-pcp-manager
  • amazon-linux-ami-2-upgrade-pcp-pmda-activemq
  • amazon-linux-ami-2-upgrade-pcp-pmda-apache
  • amazon-linux-ami-2-upgrade-pcp-pmda-bash
  • amazon-linux-ami-2-upgrade-pcp-pmda-bind2
  • amazon-linux-ami-2-upgrade-pcp-pmda-bonding
  • amazon-linux-ami-2-upgrade-pcp-pmda-cifs
  • amazon-linux-ami-2-upgrade-pcp-pmda-cisco
  • amazon-linux-ami-2-upgrade-pcp-pmda-dbping
  • amazon-linux-ami-2-upgrade-pcp-pmda-dm
  • amazon-linux-ami-2-upgrade-pcp-pmda-docker
  • amazon-linux-ami-2-upgrade-pcp-pmda-ds389
  • amazon-linux-ami-2-upgrade-pcp-pmda-ds389log
  • amazon-linux-ami-2-upgrade-pcp-pmda-elasticsearch
  • amazon-linux-ami-2-upgrade-pcp-pmda-gfs2
  • amazon-linux-ami-2-upgrade-pcp-pmda-gluster
  • amazon-linux-ami-2-upgrade-pcp-pmda-gpfs
  • amazon-linux-ami-2-upgrade-pcp-pmda-gpsd
  • amazon-linux-ami-2-upgrade-pcp-pmda-haproxy
  • amazon-linux-ami-2-upgrade-pcp-pmda-infiniband
  • amazon-linux-ami-2-upgrade-pcp-pmda-json
  • amazon-linux-ami-2-upgrade-pcp-pmda-libvirt
  • amazon-linux-ami-2-upgrade-pcp-pmda-lio
  • amazon-linux-ami-2-upgrade-pcp-pmda-lmsensors
  • amazon-linux-ami-2-upgrade-pcp-pmda-logger
  • amazon-linux-ami-2-upgrade-pcp-pmda-lustre
  • amazon-linux-ami-2-upgrade-pcp-pmda-lustrecomm
  • amazon-linux-ami-2-upgrade-pcp-pmda-mailq
  • amazon-linux-ami-2-upgrade-pcp-pmda-memcache
  • amazon-linux-ami-2-upgrade-pcp-pmda-mic
  • amazon-linux-ami-2-upgrade-pcp-pmda-mounts
  • amazon-linux-ami-2-upgrade-pcp-pmda-mysql
  • amazon-linux-ami-2-upgrade-pcp-pmda-named
  • amazon-linux-ami-2-upgrade-pcp-pmda-netfilter
  • amazon-linux-ami-2-upgrade-pcp-pmda-news
  • amazon-linux-ami-2-upgrade-pcp-pmda-nfsclient
  • amazon-linux-ami-2-upgrade-pcp-pmda-nginx
  • amazon-linux-ami-2-upgrade-pcp-pmda-nvidia-gpu
  • amazon-linux-ami-2-upgrade-pcp-pmda-oracle
  • amazon-linux-ami-2-upgrade-pcp-pmda-pdns
  • amazon-linux-ami-2-upgrade-pcp-pmda-perfevent
  • amazon-linux-ami-2-upgrade-pcp-pmda-postfix
  • amazon-linux-ami-2-upgrade-pcp-pmda-postgresql
  • amazon-linux-ami-2-upgrade-pcp-pmda-prometheus
  • amazon-linux-ami-2-upgrade-pcp-pmda-redis
  • amazon-linux-ami-2-upgrade-pcp-pmda-roomtemp
  • amazon-linux-ami-2-upgrade-pcp-pmda-rpm
  • amazon-linux-ami-2-upgrade-pcp-pmda-rsyslog
  • amazon-linux-ami-2-upgrade-pcp-pmda-samba
  • amazon-linux-ami-2-upgrade-pcp-pmda-sendmail
  • amazon-linux-ami-2-upgrade-pcp-pmda-shping
  • amazon-linux-ami-2-upgrade-pcp-pmda-slurm
  • amazon-linux-ami-2-upgrade-pcp-pmda-smart
  • amazon-linux-ami-2-upgrade-pcp-pmda-snmp
  • amazon-linux-ami-2-upgrade-pcp-pmda-summary
  • amazon-linux-ami-2-upgrade-pcp-pmda-systemd
  • amazon-linux-ami-2-upgrade-pcp-pmda-trace
  • amazon-linux-ami-2-upgrade-pcp-pmda-unbound
  • amazon-linux-ami-2-upgrade-pcp-pmda-vmware
  • amazon-linux-ami-2-upgrade-pcp-pmda-weblog
  • amazon-linux-ami-2-upgrade-pcp-pmda-zimbra
  • amazon-linux-ami-2-upgrade-pcp-pmda-zswap
  • amazon-linux-ami-2-upgrade-pcp-selinux
  • amazon-linux-ami-2-upgrade-pcp-system-tools
  • amazon-linux-ami-2-upgrade-pcp-testsuite
  • amazon-linux-ami-2-upgrade-pcp-webapi
  • amazon-linux-ami-2-upgrade-pcp-webapp-blinkenlights
  • amazon-linux-ami-2-upgrade-pcp-webapp-grafana
  • amazon-linux-ami-2-upgrade-pcp-webapp-graphite
  • amazon-linux-ami-2-upgrade-pcp-webapp-vector
  • amazon-linux-ami-2-upgrade-pcp-webjs
  • amazon-linux-ami-2-upgrade-pcp-zeroconf
  • amazon-linux-ami-2-upgrade-perl-pcp-logimport
  • amazon-linux-ami-2-upgrade-perl-pcp-logsummary
  • amazon-linux-ami-2-upgrade-perl-pcp-mmv
  • amazon-linux-ami-2-upgrade-perl-pcp-pmda
  • amazon-linux-ami-2-upgrade-python-pcp

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;