PT-2020-10007 · Suse · Suse Linux Enterprise Server+3

Johannes Segitz

·

Published

2019-12-19

·

Updated

2024-06-15

·

CVE-2019-18898

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1 openSUSE Factory trousers versions prior to 0.3.14-7.1
Description The issue allows local attackers to escalate privileges from user tss to root due to a UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package.
Recommendations For SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1, update to version 0.3.14-6.3.1 or later. For openSUSE Factory trousers versions prior to 0.3.14-7.1, update to version 0.3.14-7.1 or later.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18898
OPENSUSE-SU-2020:0015-1
OPENSUSE-SU-2020:0744-1
OPENSUSE-SU-2020_0015-1
OPENSUSE-SU-2020_0744-1
OPENSUSE-SU-2024:11476-1
SUSE-SU-2019:3349-1
SUSE-SU-2019_3349-1

Affected Products

Suse Linux Enterprise Server
Suse
Opensuse
Trousers