Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides one at an arbitrary location it is executed with root privileges
2019-03-05T16:29:00.293
2024-11-21T03:58:19.680
Modified
CVSSv3.0: 7.3 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | opensuse | supportutils | < 3.1-5.7.1 | Yes |