CVE-2019-3461

NameCVE-2019-3461
DescriptionDebian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in local privilege escalation. Mounting via rename() could potentially lead to a file being placed elsewhereon the filesystem hierarchy (e.g. /etc/cron.d/) if the directory being cleaned up was on the same physical filesystem. Fixed versions include 1.6.13+nmu1+deb9u1 and 1.6.14.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-1640-1, DSA-4365-1
Debian Bugs918956

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tmpreaper (PTS)bookworm1.6.17fixed
forky, sid, trixie1.6.18fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tmpreapersourcejessie1.6.13+nmu1+deb8u1DLA-1640-1
tmpreapersourcestretch1.6.13+nmu1+deb9u1DSA-4365-1
tmpreapersource(unstable)1.6.14918956

Search for package or bug name: Reporting problems