Low severity2.2NVD Advisory· Published Mar 15, 2019· Updated Jun 17, 2026
CVE-2018-17955
CVE-2018-17955
Description
In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems without symlink protection
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8<4.1.1+ 1 more
- (no CPE)range: <4.1.1
- (no CPE)range: unspecified
- osv-coords5 versionspkg:rpm/suse/yast2-multipath&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP4pkg:rpm/suse/yast2-multipath&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP2pkg:rpm/opensuse/yast2-multipath&distro=openSUSE%20Tumbleweedpkg:rpm/suse/yast2-multipath&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP3pkg:rpm/suse/yast2-multipath&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5
< 3.2.2-3.3.30+ 4 more
- (no CPE)range: < 3.2.2-3.3.30
- (no CPE)range: < 3.1.9-12.3.45
- (no CPE)range: < 4.4.1-1.2
- (no CPE)range: < 3.2.2-3.3.30
- (no CPE)range: < 3.2.2-3.3.30
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.