In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.
References
Link | Resource |
---|---|
https://bugzilla.suse.com/show_bug.cgi?id=1118460 | Exploit Issue Tracking Vendor Advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html |
Configurations
Information
Published : 2019-03-05 08:29
Updated : 2019-05-08 14:29
NVD link : CVE-2018-19638
Mitre link : CVE-2018-19638
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
opensuse
- supportutils