CVE-2018-19637: Static temporary filename allows overwriting of files
Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supplog, allowing local attackers to overwrite files on systems without symlink protection
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19637?
CVE-2018-19637 is a vulnerability in Supportutils before version 3.1-5.7.1.
How does CVE-2018-19637 affect systems?
CVE-2018-19637 allows local attackers to overwrite files on systems without symlink protection.
What is the severity of CVE-2018-19637?
CVE-2018-19637 has a severity rating of medium, with a severity value of 5.5.
How can I fix CVE-2018-19637?
To fix CVE-2018-19637, update to Supportutils version 3.1-5.7.1 or later.
Where can I find more information about CVE-2018-19637?
You can find more information about CVE-2018-19637 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html](http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html), [https://bugzilla.suse.com/show_bug.cgi?id=1117776](https://bugzilla.suse.com/show_bug.cgi?id=1117776).