CVE-2019-18898

UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.7 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
susetrousers
𝑥
< 0.3.14-6.3.1
susetrousers
𝑥
< 0.3.14-7.1
opensuseleap
15.1
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libtspi1
suse enterprise desktop 15 SP1
0.3.14-6.3.1
fixed
suse enterprise desktop 15 SP2
0.3.14-6.3.1
fixed
suse enterprise desktop 15 SP3
0.3.14-6.3.1
fixed
suse enterprise desktop 15 SP4
0.3.15-150400.1.10
fixed
suse enterprise desktop 15 SP5
0.3.15-150400.1.10
fixed
suse enterprise desktop 15 SP6
0.3.15-150600.8.2
fixed
suse enterprise desktop 15 SP7
0.3.15-150600.10.3.1
fixed
suse enterprise sap 15 SP1
0.3.14-6.3.1
fixed
suse enterprise sap 15 SP2
0.3.14-6.3.1
fixed
suse enterprise sap 15 SP3
0.3.14-6.3.1
fixed
suse enterprise sap 15 SP4
0.3.15-150400.1.10
fixed
suse enterprise sap 15 SP5
0.3.15-150400.1.10
fixed
suse enterprise sap 15 SP6
0.3.15-150600.8.2
fixed
suse enterprise sap 15 SP7
0.3.15-150600.10.3.1
fixed
suse enterprise server 15 SP1
0.3.14-6.3.1
fixed
suse enterprise server 15 SP2
0.3.14-6.3.1
fixed
suse enterprise server 15 SP3
0.3.14-6.3.1
fixed
suse enterprise server 15 SP4
0.3.15-150400.1.10
fixed
suse enterprise server 15 SP5
0.3.15-150400.1.10
fixed
suse enterprise server 15 SP6
0.3.15-150600.8.2
fixed
suse enterprise server 15 SP7
0.3.15-150600.10.3.1
fixed
trousers
suse enterprise desktop 15 SP1
0.3.14-6.3.1
fixed
suse enterprise desktop 15 SP2
0.3.14-6.3.1
fixed
suse enterprise desktop 15 SP3
0.3.14-6.3.1
fixed
suse enterprise desktop 15 SP4
0.3.15-150400.1.10
fixed
suse enterprise desktop 15 SP5
0.3.15-150400.1.10
fixed
suse enterprise desktop 15 SP6
0.3.15-150600.8.2
fixed
suse enterprise desktop 15 SP7
0.3.15-150600.10.3.1
fixed
suse enterprise sap 15 SP1
0.3.14-6.3.1
fixed
suse enterprise sap 15 SP2
0.3.14-6.3.1
fixed
suse enterprise sap 15 SP3
0.3.14-6.3.1
fixed
suse enterprise sap 15 SP4
0.3.15-150400.1.10
fixed
suse enterprise sap 15 SP5
0.3.15-150400.1.10
fixed
suse enterprise sap 15 SP6
0.3.15-150600.8.2
fixed
suse enterprise sap 15 SP7
0.3.15-150600.10.3.1
fixed
suse enterprise server 15 SP1
0.3.14-6.3.1
fixed
suse enterprise server 15 SP2
0.3.14-6.3.1
fixed
suse enterprise server 15 SP3
0.3.14-6.3.1
fixed
suse enterprise server 15 SP4
0.3.15-150400.1.10
fixed
suse enterprise server 15 SP5
0.3.15-150400.1.10
fixed
suse enterprise server 15 SP6
0.3.15-150600.8.2
fixed
suse enterprise server 15 SP7
0.3.15-150600.10.3.1
fixed
trousers-devel
suse enterprise desktop 15 SP1
0.3.14-6.3.1
fixed
suse enterprise desktop 15 SP2
0.3.14-6.3.1
fixed
suse enterprise desktop 15 SP3
0.3.14-6.3.1
fixed
suse enterprise desktop 15 SP4
0.3.15-150400.1.10
fixed
suse enterprise desktop 15 SP5
0.3.15-150400.1.10
fixed
suse enterprise desktop 15 SP6
0.3.15-150600.8.2
fixed
suse enterprise desktop 15 SP7
0.3.15-150600.10.3.1
fixed
suse enterprise sap 15 SP1
0.3.14-6.3.1
fixed
suse enterprise sap 15 SP2
0.3.14-6.3.1
fixed
suse enterprise sap 15 SP3
0.3.14-6.3.1
fixed
suse enterprise sap 15 SP4
0.3.15-150400.1.10
fixed
suse enterprise sap 15 SP5
0.3.15-150400.1.10
fixed
suse enterprise sap 15 SP6
0.3.15-150600.8.2
fixed
suse enterprise sap 15 SP7
0.3.15-150600.10.3.1
fixed
suse enterprise server 15 SP1
0.3.14-6.3.1
fixed
suse enterprise server 15 SP2
0.3.14-6.3.1
fixed
suse enterprise server 15 SP3
0.3.14-6.3.1
fixed
suse enterprise server 15 SP4
0.3.15-150400.1.10
fixed
suse enterprise server 15 SP5
0.3.15-150400.1.10
fixed
suse enterprise server 15 SP6
0.3.15-150600.8.2
fixed
suse enterprise server 15 SP7
0.3.15-150600.10.3.1
fixed