CVE-2018-19637

Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection
Configurations

Configuration 1 (hide)

cpe:2.3:a:opensuse:supportutils:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-03-05 16:29

Updated : 2024-02-04 20:03


NVD link : CVE-2018-19637

Mitre link : CVE-2018-19637

CVE.ORG link : CVE-2018-19637


JSON object : View

Products Affected

opensuse

  • supportutils
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')

CWE-377

Insecure Temporary File