Vulnerability Description
If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands as root.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensuse | Supportutils | < 3.1-5.7.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html
- https://bugzilla.suse.com/show_bug.cgi?id=1118462
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html
- https://bugzilla.suse.com/show_bug.cgi?id=1118462
FAQ
What is CVE-2018-19639?
CVE-2018-19639 is a vulnerability with a CVSS score of 6.7 (MEDIUM). If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands ...
How severe is CVE-2018-19639?
CVE-2018-19639 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19639?
Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Supportutils.