HIGH
Code execution if run with command line switch -v
Published Mar 5, 2019
7.8
HIGHCVSS 3.0
EPSS 0.50%
Description
If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands as root.
Affected products
-
Affected
- ≥ unspecified, < 3.1-5.7.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| SUSE | Supportutils | unknown | Affected
|
- < 3.1-5.7.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html vendor-advisoryx_refsource_SUSE
- https://bugzilla.suse.com/show_bug.cgi?id=1118462 x_refsource_CONFIRM
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-11324 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html | vendor-advisoryx_refsource_SUSE | |
| https://bugzilla.suse.com/show_bug.cgi?id=1118462 | x_refsource_CONFIRM | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-11324 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microfocus
Published Mar 5, 2019
Updated Sep 16, 2024
Reserved Nov 28, 2018
Link CVE-2018-19639
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data