7.2
CVSSv2

CVE-2019-18898

Published: 23/01/2020 Updated: 10/11/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions before 0.3.14-6.3.1. openSUSE Factory trousers versions before 0.3.14-7.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

suse trousers

opensuse leap 15.1