First published: Thu Jan 23 2020(Updated: )
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to 3.1-lp151.3.3.1.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Apt-cacher-ng Project Apt-cacher-ng | <3.1-lp151.3.3.1 | |
openSUSE Leap | =15.1 | |
Opensuse Backports | =sle-15-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
This vulnerability affects the apt-cacher-ng package of openSUSE Leap 15.1 versions prior to 3.1-lp151.3.3.1.
The vulnerability in apt-cacher-ng can allow local attackers to influence the outcome of operations.
The severity rating of this vulnerability is medium, with a CVSS score of 5.5.
To fix this vulnerability, update the apt-cacher-ng package to version 3.1-lp151.3.3.1 or later.
You can find more information about CVE-2019-18899 in the references provided: http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00057.html, http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00065.html, https://bugzilla.suse.com/show_bug.cgi?id=1157703