CVE-2019-18900
published 2020-01-24CVE-2019-18900: : Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed…
low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.0 libzypp versions prior to 16.21.2-27.68.1. SUSE Linux Enterprise Server 12 libzypp versions prior to 16.21.2-2.45.1. SUSE Linux Enterprise Server 15 17.19.0-3.34.1.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libzypp | < libzypp 17.25.5-2 (bookworm) | libzypp 17.25.5-2 (bookworm) |
| opensuse | libzypp | < 16.21.2-27.68.1 | 16.21.2-27.68.1 |
| opensuse | libzypp | < 16.21.2-2.45.1 | 16.21.2-2.45.1 |
| opensuse | libzypp | < 17.19.0-3.34.1 | 17.19.0-3.34.1 |
| opensuse | libzypp | >= 0 < 17.25.5-2 | 17.25.5-2 |
| opensuse | libzypp | >= 0 < 17.25.5-2 | 17.25.5-2 |
| opensuse | libzypp | >= 0 < 17.25.5-2 | 17.25.5-2 |
| opensuse | libzypp | >= 0 < 17.25.5-2 | 17.25.5-2 |
| suse | caas_platform_3.0 | >= libzypp < 16.21.2-27.68.1 | 16.21.2-27.68.1 |
| suse | suse_linux_enterprise_server_12 | >= libzypp < 16.21.2-2.45.1 | 16.21.2-2.45.1 |
| suse | suse_linux_enterprise_server_15 | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv3.3LOW