PT-2020-1514 · Suse · Suse Caas Platform+3
Matthias Gerstner
·
Published
2020-01-13
·
Updated
2024-06-15
·
CVE-2019-18900
CVSS v3.1
4.0
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SUSE CaaS Platform versions prior to 16.21.2-27.68.1
SUSE Linux Enterprise Server 12 versions prior to 16.21.2-2.45.1
SUSE Linux Enterprise Server 15 version 17.19.0-3.34.1
Description
The issue is related to incorrect default permissions in the libzypp library of SUSE products, allowing local attackers to read a cookie store used by libzypp and exposing private cookies. This may enable an attacker to gain unauthorized access to information.
Recommendations
For SUSE CaaS Platform versions prior to 16.21.2-27.68.1, update to version 16.21.2-27.68.1 or later.
For SUSE Linux Enterprise Server 12 versions prior to 16.21.2-2.45.1, update to version 16.21.2-2.45.1 or later.
For SUSE Linux Enterprise Server 15 version 17.19.0-3.34.1, update to a version later than 17.19.0-3.34.1.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse Caas Platform
Suse Linux Enterprise Server
Suse
Libzypp