First published: Mon Mar 02 2020(Updated: )
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-28.26.1. openSUSE Leap 15.1 wicked versions prior to 0.6.60-lp151.2.9.1. openSUSE Factory wicked versions prior to 0.6.62.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Leap | =15.1 | |
SUSE Linux Enterprise Server | =12 | |
SUSE Linux Enterprise Server | =15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18903 is a Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, openSUSE Leap 15.1, and Factory that allows remote attackers to cause DoS or potentially code execution.
SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1 are affected by CVE-2019-18903.
CVE-2019-18903 has a severity rating of 9.8 (critical).
The Common Weakness Enumeration (CWE) ID for CVE-2019-18903 is 416.
To fix CVE-2019-18903, upgrade to wicked version 0.6.60-2.18.1 or later.