First published: Tue Mar 05 2019(Updated: )
Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides one at an arbitrary location it is executed with root privileges
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Opensuse Supportutils | <3.1-5.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19636 is a vulnerability that exists in Supportutils, before version 3.1-5.7.1, when run with the command line argument -A.
CVE-2018-19636 has a severity rating of 7.8 (high).
When Supportutils is run with the -A command line argument, it searches the file system for a ndspath binary. If an attacker provides one at an arbitrary location, it is executed with root privileges.
To fix CVE-2018-19636, upgrade Supportutils to version 3.1-5.7.1 or later.
Yes, you can find more information about CVE-2018-19636 at the following references: [link1](http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html) and [link2](https://bugzilla.suse.com/show_bug.cgi?id=1117751).