CVE-2018-19637 LOW

CVE-2018-19637: Static temporary filename allows overwriting of files

Vendor Suse
Product supportutils
Weakness CWE-377
Published March 5, 2019
Last update September 16, 2024

CVSS base score

2.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection

Key dates

02Disclosure timeline

March 5, 2019 CVE published
September 16, 2024 Record updated