CVE-2018-19637
Static temporary filename allows overwriting of files
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection
Supportutils, en versiones anteriores a la 3.1-5.7.1, escribía datos al archivo estático tmp/supp_log, lo que permitía a los atacantes locales sobrescribir archivos en sistemas sin protecciones symlink.
An update that solves 5 vulnerabilities and has 5 fixes is now available. This update for hostinfo, supportutils fixes the following issues. Security issues fixed for supportutils. Fixed an issue where users could kill arbitrary processes. Fixed an issue where users could overwrite arbitrary log files. Fixed a code execution if run with -v. Fixed an issue where static temporary filename could allow overwriting of files. Fixed a local root exploit via inclusion of attacker controlled shell script. Other issues fixed for supportutils. Issues fixed in hostinfo. This update was imported from the SUSE:SLE-12:Update update project.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-28 CVE Reserved
- 2019-03-05 CVE Published
- 2024-09-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
- CWE-377: Insecure Temporary File
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://bugzilla.suse.com/show_bug.cgi?id=1117776 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opensuse Search vendor "Opensuse" | Supportutils Search vendor "Opensuse" for product "Supportutils" | < 3.1-5.7.1 Search vendor "Opensuse" for product "Supportutils" and version " < 3.1-5.7.1" | - |
Affected
|