Vulnerability Description
If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensuse | Supportutils | < 3.1-5.7.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html
- https://bugzilla.suse.com/show_bug.cgi?id=1118463
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html
- https://bugzilla.suse.com/show_bug.cgi?id=1118463
FAQ
What is CVE-2018-19640?
CVE-2018-19640 is a vulnerability with a CVSS score of 4.4 (MEDIUM). If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local mach...
How severe is CVE-2018-19640?
CVE-2018-19640 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19640?
Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Supportutils.