CVE-2018-19637

Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.8 LOW
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
Affected Products (NVD)
VendorProductVersion
opensusesupportutils
𝑥
< 3.1-5.7.1
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
hostinfo
suse enterprise sap 12 SP2
1.0.1-19.5.1
fixed
suse enterprise sap 12 SP3
1.0.1-19.5.1
fixed
suse enterprise sap 12 SP4
1.0.1-19.5.1
fixed
suse enterprise server 12
1.0.1-19.5.1
fixed
suse enterprise server 12 SP1
1.0.1-19.5.1
fixed
suse enterprise server 12 SP2
1.0.1-19.5.1
fixed
suse enterprise server 12 SP3
1.0.1-19.5.1
fixed
suse enterprise server 12 SP4
1.0.1-19.5.1
fixed
supportutils
suse enterprise desktop 15 SP3
3.1.15-1.1
fixed
suse enterprise desktop 15 SP4
3.1.20-150300.7.35.10.1
fixed
suse enterprise sap 12 SP2
3.0-95.21.1
fixed
suse enterprise sap 12 SP3
3.0-95.21.1
fixed
suse enterprise sap 12 SP4
3.0-95.21.1
fixed
suse enterprise sap 15 SP3
3.1.15-1.1
fixed
suse enterprise sap 15 SP4
3.1.20-150300.7.35.10.1
fixed
suse enterprise server 12
3.0-95.21.1
fixed
suse enterprise server 12 SP1
3.0-95.21.1
fixed
suse enterprise server 12 SP2
3.0-95.21.1
fixed
suse enterprise server 12 SP3
3.0-95.21.1
fixed
suse enterprise server 12 SP4
3.0-95.21.1
fixed
suse enterprise server 15 SP3
3.1.15-1.1
fixed
suse enterprise server 15 SP4
3.1.20-150300.7.35.10.1
fixed