First published: Mon Mar 02 2020(Updated: )
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-3.21.1. openSUSE Leap 15.1 wicked versions prior to 0.6.60-lp151.2.6.1. openSUSE Factory wicked versions prior to 0.6.62.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Leap | =15.1 | |
SUSE Linux Enterprise Server | =12 | |
SUSE Linux Enterprise Server | =15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18902 is a Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory that allows remote attackers to cause DoS or potentially code execution.
The affected software versions are SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1, SUSE Linux Enterprise Server 15, openSUSE Leap 15.1, and Factory.
CVE-2019-18902 has a severity rating of critical with a CVSS score of 9.8.
CVE-2019-18902 can be exploited by remote attackers to cause DoS or potentially execute code.
Yes, a fix for CVE-2019-18902 is available. It is recommended to update to wicked version 0.6.60-3.5.1 or later for SUSE Linux Enterprise Server 12.