CVE-2019-18899: apt-cacher-ng insecure use of /run/apt-cacher-ng
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to 3.1-lp151.3.3.1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability status of CVE-2019-18899?
This vulnerability affects the apt-cacher-ng package of openSUSE Leap 15.1 versions prior to 3.1-lp151.3.3.1.
How does CVE-2019-18899 affect openSUSE Leap 15.1?
The vulnerability in apt-cacher-ng can allow local attackers to influence the outcome of operations.
What is the severity rating of CVE-2019-18899?
The severity rating of this vulnerability is medium, with a CVSS score of 5.5.
How can I fix CVE-2019-18899?
To fix this vulnerability, update the apt-cacher-ng package to version 3.1-lp151.3.3.1 or later.
Where can I find more information about CVE-2019-18899?
You can find more information about CVE-2019-18899 in the references provided: http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00057.html, http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00065.html, https://bugzilla.suse.com/show_bug.cgi?id=1157703