First published: Thu Jan 23 2020(Updated: )
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Suse Trousers | <0.3.14-6.3.1 | |
SUSE SUSE Linux Enterprise Server | =15-sp1 | |
Suse Trousers | <0.3.14-7.1 | |
SUSE openSUSE Factory | ||
openSUSE Leap | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18898 is a vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1 and openSUSE Factory that allows local attackers to escalate privileges.
The severity of CVE-2019-18898 is high, with a CVSS score of 7.8.
CVE-2019-18898 affects SUSE Linux Enterprise Server 15 SP1 if the trousers package version is prior to 0.3.14-6.3.1.
To fix CVE-2019-18898 on SUSE Linux Enterprise Server 15 SP1, update the trousers package to version 0.3.14-6.3.1 or later.
Other versions or distributions, such as openSUSE Factory and openSUSE Leap 15.1, may also be affected depending on the trousers package version.