CVE-2019-3684: susemanager installer creates world-readable swap files
SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade created world-readable swap files on systems that don't have a swap already configured and don't have btrfs as filesystem
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SUSE Manager and Uyuni vulnerability?
The vulnerability ID for this SUSE Manager and Uyuni vulnerability is CVE-2019-3684.
What is the severity level of CVE-2019-3684?
The severity level of CVE-2019-3684 is medium.
How does CVE-2019-3684 affect SUSE Manager and Uyuni?
CVE-2019-3684 creates world-readable swap files on systems that don't have a swap already configured and don't have btrfs as filesystem in SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade.
How can I fix CVE-2019-3684?
To fix CVE-2019-3684, update SUSE Manager to version 4.0.7 or later and Uyuni to a commit after 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade.
Where can I find more information about CVE-2019-3684?
You can find more information about CVE-2019-3684 at the following link: https://bugzilla.suse.com/show_bug.cgi?id=1131954.