CVE-2018-19638
published 2019-03-05CVE-2018-19638: In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the…
PriorityP422medium4.7CVSS 3.0
AVLACHPRLUINSUCNIHAN
EPSS
0.40%
32.1th percentile
In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | supportutils | < 3.1-5.7.1 | 3.1-5.7.1 |
| suse | supportutils | >= unspecified < 3.1-5.7.1 | 3.1-5.7.1 |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8w66-9hvh-6jfx: In supportutils, before version 3
ghsa_unreviewed·2022-05-14
CVE-2018-19638 [MEDIUM] CWE-59 GHSA-8w66-9hvh-6jfx: In supportutils, before version 3
In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.
GHSA
GHSA-7g5j-9rpf-g2r7: If the attacker manages to create files in the directory used to collect log files in supportutils before version 3
ghsa_unreviewed·2022-05-14·CVSS 2.2
CVE-2018-19640 [LOW] CWE-20 GHSA-7g5j-9rpf-g2r7: If the attacker manages to create files in the directory used to collect log files in supportutils before version 3
If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine.
GHSA
GHSA-82r4-3q2m-qgrm: If supportutils before version 3
ghsa_unreviewed·2022-05-13·CVSS 2.2
CVE-2018-19639 [LOW] GHSA-82r4-3q2m-qgrm: If supportutils before version 3
If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands as root.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-03-05
Published