CVE-2019-3697

HIGH

gnump3d < 3.0 - Privilege Escalation via Symlink Following

Title source: llm
STIX 2.1

Description

UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user gnump3d to root. This issue affects: openSUSE Leap 15.1 gnump3d version 3.0-lp151.2.1 and prior versions.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.suse.com/show_bug.cgi?id=1154229

Scores

CVSS v3 7.7
EPSS 0.0013
EPSS Percentile 31.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-59
Status published
Products (2)
gnu/gnump3d < 3.0
opensuse/leap 15.1
Published Jan 24, 2020
Tracked Since Feb 18, 2026