Skip to main content

Vendor/product archive

opensuse / supportutils CVEs

Beta · best-effort

6 CVEs tagged to opensuse / supportutils0 Critical, 1 High, 3 Medium, 2 Low, 0 Unrated.

CVE-2018-19640

Published Mar 5, 2019

If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary proces…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19639

Published Mar 5, 2019

If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execut…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19638

Published Mar 5, 2019

In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by…

CVSS 2.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-19637

Published Mar 5, 2019

Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-19636

Published Mar 5, 2019

Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides one at an arbitrary location…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1