CVE-2019-3688: Suse Linux Enterprise Server
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by changing the binary
Affected products
- Suse Suse Linux Enterprise Server: version 12 only; version 15 only
Published 2019-10-07. Last modified 2026-06-17.