trousers: Local privilege escalation from tss to root
Published Jan 23, 2020
7.8
HIGHCVSS 3.1
EPSS 0.48%
Description
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.
Affected products
-
Affected
- ≥ trousers, < 0.3.14-6.3.1
-
Affected
- ≥ trousers, < 0.3.14-7.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| SUSE | SUSE Linux Enterprise Server 15 SP1 | unknown | Affected
|
| openSUSE | Factory | unknown | Affected
|
Configuration 1
Running on/with
- 15
Configuration 2
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 5
trousers
Not affected
Red Hat Enterprise Linux 6
trousers
Not affected
Red Hat Enterprise Linux 7
trousers
Not affected
Red Hat Enterprise Linux 8
trousers
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | trousers | Not affected | n/a |
| Red Hat Enterprise Linux 6 | trousers | Not affected | n/a |
| Red Hat Enterprise Linux 7 | trousers | Not affected | n/a |
| Red Hat Enterprise Linux 8 | trousers | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The trousers versions as shipped as Red Hat Enterprise Linux 5, 6, 7 and 8 are not affected by this issue. The flaw resides on the post transaction scriptlet from the RPM package. This scriptlet doesn't exists on Red Hat Enterprise Linux RPM spec file.
References (7)
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00066.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-18898 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1787080 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1157651 x_refsource_CONFIRMExploitIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8579 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-18898
- https://www.cve.org/CVERecord?id=CVE-2019-18898
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00066.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-18898 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1787080 | Issue Tracking | |
| https://bugzilla.suse.com/show_bug.cgi?id=1157651 | x_refsource_CONFIRMExploitIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8579 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-18898 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-18898 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data