CVE-2018-19640: Code execution if run with command line switch -v
If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19640?
CVE-2018-19640 is a vulnerability that allows an attacker to kill arbitrary processes on the local machine by creating files in the directory used to collect log files in supportutils before version 3.1-5.7.1.
What is the severity of CVE-2018-19640?
CVE-2018-19640 has a severity rating of 5.5, which is considered medium.
Which software is affected by CVE-2018-19640?
CVE-2018-19640 affects Opensuse Supportutils version up to and excluding 3.1-5.7.1.
How can an attacker exploit CVE-2018-19640?
An attacker can exploit CVE-2018-19640 by creating files in the directory used to collect log files in supportutils.
Is there a fix for CVE-2018-19640?
Yes, upgrading to version 3.1-5.7.1 or above of Opensuse Supportutils will fix CVE-2018-19640.