First published: Tue Mar 05 2019(Updated: )
Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Opensuse Supportutils | <3.1-5.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19637 is a vulnerability in Supportutils before version 3.1-5.7.1.
CVE-2018-19637 allows local attackers to overwrite files on systems without symlink protection.
CVE-2018-19637 has a severity rating of medium, with a severity value of 5.5.
To fix CVE-2018-19637, update to Supportutils version 3.1-5.7.1 or later.
You can find more information about CVE-2018-19637 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html](http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html), [https://bugzilla.suse.com/show_bug.cgi?id=1117776](https://bugzilla.suse.com/show_bug.cgi?id=1117776).