A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-15763 A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation.
Fixes

Solution

To mitigate these vulnerabilities, Lenovo recommends installing Lenovo software updates through Lenovo Vantage, Lenovo System Update, or Windows Update. Updates delivered through Update Retriever, Thin Installer, and System Update are also not affected. Lenovo installation packages version 1.2.9.3 or later are not affected.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-17T00:25:55.970Z

Reserved: 2019-01-11T00:00:00

Link: CVE-2019-6196

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-09T20:15:11.787

Modified: 2024-11-21T04:46:09.287

Link: CVE-2019-6196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.