CVE-2018-19639
Code execution if run with command line switch -v
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands as root.
Si supportutils, en versiones anteriores a la 3.1-5.7.1, se ejecuta con -v para realizar una verificación rpm y si el atacante consigue manipular la entrada rpm (p.ej., con CVE-2018-19638), éste puede ejecutar comandos arbitrarios como root.
An update that solves 5 vulnerabilities and has 5 fixes is now available. This update for hostinfo, supportutils fixes the following issues. Security issues fixed for supportutils. Fixed an issue where users could kill arbitrary processes. Fixed an issue where users could overwrite arbitrary log files. Fixed a code execution if run with -v. Fixed an issue where static temporary filename could allow overwriting of files. Fixed a local root exploit via inclusion of attacker controlled shell script. Other issues fixed for supportutils. Issues fixed in hostinfo. This update was imported from the SUSE:SLE-12:Update update project.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-28 CVE Reserved
- 2019-03-05 CVE Published
- 2024-09-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://bugzilla.suse.com/show_bug.cgi?id=1118462 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opensuse Search vendor "Opensuse" | Supportutils Search vendor "Opensuse" for product "Supportutils" | < 3.1-5.7.1 Search vendor "Opensuse" for product "Supportutils" and version " < 3.1-5.7.1" | - |
Affected
|