CVE-2019-18898
published 2020-01-23CVE-2019-18898: UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.48%
38.5th percentile
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | factory | >= trousers < 0.3.14-7.1 | 0.3.14-7.1 |
| opensuse | leap | — | — |
| suse | suse_linux_enterprise_server_15_sp1 | >= trousers < 0.3.14-6.3.1 | 0.3.14-6.3.1 |
| suse | trousers | < 0.3.14-6.3.1 | 0.3.14-6.3.1 |
| suse | trousers | < 0.3.14-7.1 | 0.3.14-7.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
trousers: local privilege escalation from tss to root
vendor_redhat·2019-11-25·CVSS 7.7
CVE-2019-18898 [HIGH] CWE-266 trousers: local privilege escalation from tss to root
trousers: local privilege escalation from tss to root
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.
Statement: The trousers versions as shipped as Red Hat Enterprise Linux 5, 6, 7 and 8 are not affected by this issue. The flaw resides on the post transaction scriptlet from the RPM package. This scriptlet doesn't exists on Red Hat Enterprise Linux RPM spec file.
Package: trousers (Red Hat Enterprise Linux 5) - Not affected
Package: trousers (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-w5w4-523j-qm3v: UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed loc
ghsa_unreviewed·2022-05-24
CVE-2019-18898 [HIGH] CWE-59 GHSA-w5w4-523j-qm3v: UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed loc
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.
No detection rules found.
No public exploits indexed.
2020-01-23
Published