CVE-2018-19638

CWE-377CWE-593 documents3 sources
Severity
4.7MEDIUM
EPSS
0.0%
top 87.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 14

Description

In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:NExploitability: 0.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5suse/supportutilsunspecified3.1-5.7.1
NVDopensuse/supportutils< 3.1-5.7.1

🔴Vulnerability Details

2
GHSA
GHSA-8w66-9hvh-6jfx: In supportutils, before version 32022-05-14
CVEList
User can overwrite arbitrary log files in support tar2019-03-05
CVE-2018-19638 (MEDIUM CVSS 4.7) | In supportutils | cvebase.io