CVE-2019-10220

HIGH

Description

Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.

References

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10220

https://security.netapp.com/advisory/ntap-20200103-0001/

https://usn.ubuntu.com/4226-1/

Details

Source: MITRE

Published: 2019-11-27

Updated: 2020-01-03

Type: CWE-22

Risk Information

CVSS v2.0

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

CVSS v3.0

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:4.9.0:*:*:*:*:*:*:*

Tenable Plugins

View all (31 total)

IDNameProductFamilySeverity
137516EulerOS 2.0 SP2 : kernel (EulerOS-SA-2020-1674)NessusHuawei Local Security Checks
critical
136239EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2020-1536)NessusHuawei Local Security Checks
critical
135614EulerOS Virtualization 3.0.2.2 : kernel (EulerOS-SA-2020-1452)NessusHuawei Local Security Checks
high
135525EulerOS 2.0 SP3 : kernel (EulerOS-SA-2020-1396)NessusHuawei Local Security Checks
critical
134240Debian DLA-2114-1 : linux-4.9 security updateNessusDebian Local Security Checks
critical
133101Debian DLA-2068-1 : linux security updateNessusDebian Local Security Checks
critical
132925SUSE SLES12 Security Update : kernel (SUSE-SU-2020:0093-1)NessusSuSE Local Security Checks
critical
132690Ubuntu 18.04 LTS / 19.04 : linux, linux-aws, linux-aws-5.0, linux-azure, linux-gcp, linux-gke-5.0, (USN-4226-1)NessusUbuntu Local Security Checks
critical
132605EulerOS 2.0 SP8 : kernel (EulerOS-SA-2020-1012)NessusHuawei Local Security Checks
critical
132360EulerOS 2.0 SP5 : kernel (EulerOS-SA-2019-2693)NessusHuawei Local Security Checks
high
132071SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:3295-1)NessusSuSE Local Security Checks
high
132008SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3263-1)NessusSuSE Local Security Checks
high
132007SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3261-1)NessusSuSE Local Security Checks
high
132006SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3260-1)NessusSuSE Local Security Checks
high
132005SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3258-1)NessusSuSE Local Security Checks
high
132002SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3233-1)NessusSuSE Local Security Checks
high
132001SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3232-1)NessusSuSE Local Security Checks
high
132000SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3230-1)NessusSuSE Local Security Checks
high
131999SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3228-1)NessusSuSE Local Security Checks
high
131833SUSE SLES12 Security Update : kernel (SUSE-SU-2019:3200-1)NessusSuSE Local Security Checks
high
131120SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2984-1)NessusSuSE Local Security Checks
critical
131061openSUSE Security Update : the Linux Kernel (openSUSE-2019-2507)NessusSuSE Local Security Checks
high
131057openSUSE Security Update : the Linux Kernel (openSUSE-2019-2503)NessusSuSE Local Security Checks
high
130951SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2953-1)NessusSuSE Local Security Checks
high
130950SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2950-1) (SACK Panic)NessusSuSE Local Security Checks
critical
130949SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2949-1)NessusSuSE Local Security Checks
critical
130948SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2019:2948-1)NessusSuSE Local Security Checks
high
130947SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:2947-1)NessusSuSE Local Security Checks
high
130946SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:2946-1)NessusSuSE Local Security Checks
high
130424SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2829-1)NessusSuSE Local Security Checks
high
130423SUSE SLES12 Security Update : kernel (SUSE-SU-2019:2821-1) (SACK Panic) (SACK Slowness)NessusSuSE Local Security Checks
high