CVE-2019-18898

CWE-59CWE-2665 documents5 sources
Severity
7.8HIGH
EPSS
0.1%
top 64.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateMay 24

Description

UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.5 | Impact: 5.2

Affected Packages4 packages

CVEListV5suse/suse_linux_enterprise_server_15_sp1trousers0.3.14-6.3.1
NVDsuse/trousers< 0.3.14-6.3.1+1
CVEListV5opensuse/factorytrousers0.3.14-7.1
NVDopensuse/leap15.1

🔴Vulnerability Details

2
GHSA
GHSA-w5w4-523j-qm3v: UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed loc2022-05-24
CVEList
trousers: Local privilege escalation from tss to root2020-01-23

📋Vendor Advisories

1
Red Hat
trousers: local privilege escalation from tss to root2019-11-25

💬Community

1
Bugzilla
CVE-2019-18898 trousers: local privilege escalation from tss to root2019-12-30
CVE-2019-18898 (HIGH CVSS 7.8) | UNIX Symbolic Link (Symlink) Follow | cvebase.io