CVE-2018-19638

In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.2 LOW
LOCAL
HIGH
LOW
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
opensusesupportutils
𝑥
< 3.1-5.7.1
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
hostinfo
suse enterprise sap 12 SP2
1.0.1-19.5.1
fixed
suse enterprise sap 12 SP3
1.0.1-19.5.1
fixed
suse enterprise sap 12 SP4
1.0.1-19.5.1
fixed
suse enterprise server 12
1.0.1-19.5.1
fixed
suse enterprise server 12 SP1
1.0.1-19.5.1
fixed
suse enterprise server 12 SP2
1.0.1-19.5.1
fixed
suse enterprise server 12 SP3
1.0.1-19.5.1
fixed
suse enterprise server 12 SP4
1.0.1-19.5.1
fixed
supportutils
suse enterprise sap 12 SP2
3.0-95.21.1
fixed
suse enterprise sap 12 SP3
3.0-95.21.1
fixed
suse enterprise sap 12 SP4
3.0-95.21.1
fixed
suse enterprise server 12
3.0-95.21.1
fixed
suse enterprise server 12 SP1
3.0-95.21.1
fixed
suse enterprise server 12 SP2
3.0-95.21.1
fixed
suse enterprise server 12 SP3
3.0-95.21.1
fixed
suse enterprise server 12 SP4
3.0-95.21.1
fixed