High severity7.7NVD Advisory· Published Jan 23, 2020· Updated Jun 17, 2026
CVE-2019-18898
CVE-2019-18898
Description
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords3 versionspkg:rpm/opensuse/trousers&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/trousers&distro=openSUSE%20Tumbleweedpkg:rpm/suse/trousers&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1
< 0.3.14-lp151.4.3.1+ 2 more
- (no CPE)range: < 0.3.14-lp151.4.3.1
- (no CPE)range: < 0.3.15-1.7
- (no CPE)range: < 0.3.14-6.3.1
- openSUSE/Factoryv5Range: trousers
- Range: trousers
Patches
Vulnerability mechanics
References
2- bugzilla.suse.com/show_bug.cginvdExploitIssue TrackingVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2020-05/msg00066.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.