UBUNTU-CVE-2019-18899

Source
https://ubuntu.com/security/CVE-2019-18899
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-18899.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2019-18899
Upstream
Withdrawn
2025-07-08T10:45:35Z
Published
2020-01-23T15:15:00Z
Modified
2025-07-08T14:32:19.415509Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • - low
Summary
[none]
Details

The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to 3.1-lp151.3.3.1.

References

Affected packages

Ubuntu:Pro:16.04:LTS / apt-cacher-ng

Package

Name
apt-cacher-ng
Purl
pkg:deb/ubuntu/apt-cacher-ng@0.9.1-1ubuntu1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.8.5-1
0.8.6-1
0.8.7-1
0.8.8-1
0.8.9-1
0.8.9-1ubuntu1
0.9.1-1ubuntu1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-18899.json"

Ubuntu:Pro:18.04:LTS / apt-cacher-ng

Package

Name
apt-cacher-ng
Purl
pkg:deb/ubuntu/apt-cacher-ng@3.1-1build1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other
3-5
3.*
3.1-1
3.1-1build1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-18899.json"