Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-18898

Опубликовано: 25 нояб. 2019
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.

Отчет

The trousers versions as shipped as Red Hat Enterprise Linux 5, 6, 7 and 8 are not affected by this issue. The flaw resides on the post transaction scriptlet from the RPM package. This scriptlet doesn't exists on Red Hat Enterprise Linux RPM spec file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5trousersNot affected
Red Hat Enterprise Linux 6trousersNot affected
Red Hat Enterprise Linux 7trousersNot affected
Red Hat Enterprise Linux 8trousersNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=1787080trousers: local privilege escalation from tss to root

EPSS

Процентиль: 36%
0.00148
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
около 6 лет назад

UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.

suse-cvrf
больше 5 лет назад

Security update for trousers

suse-cvrf
около 6 лет назад

Security update for trousers

suse-cvrf
около 6 лет назад

Security update for trousers

CVSS3: 7.8
github
больше 3 лет назад

UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.

EPSS

Процентиль: 36%
0.00148
Низкий

3.1 Low

CVSS3