CVE-2018-19639: Code execution if run with command line switch -v
Published Mar 5, 2019
·Updated
If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands as root.
Affected Software
1 affected component
openSUSE Supportutils<3.1-5.7.1
Event History
Mar 5, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2018-19639?
CVE-2018-19639 is a vulnerability in supportutils prior to version 3.1-5.7.1 that allows an attacker to execute arbitrary commands as root.
2
How can an attacker exploit CVE-2018-19639?
An attacker can exploit CVE-2018-19639 by manipulating the rpm listing when running supportutils with the -v option for rpm verification.
3
What is the severity of CVE-2018-19639?
The severity of CVE-2018-19639 is high, with a severity score of 7.8.
4
What is the affected software for CVE-2018-19639?
The affected software for CVE-2018-19639 is Opensuse Supportutils version up to 3.1-5.7.1.
5
How can I fix CVE-2018-19639?
To fix CVE-2018-19639, you should update supportutils to version 3.1-5.7.1 or later.