CVE-2018-19046

Name
CVE-2018-19046
Description
keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access for the attacker and write access for the keepalived process, then this potentially leaked sensitive information.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/acassen/keepalived/issues/1048
Issue Tracking https://bugzilla.suse.com/show_bug.cgi?id=1015141
Third Party Advisory https://security.gentoo.org/glsa/201903-01

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:keepalived:keepalived:2.0.8:*:*:*:*:*:*:* keepalived == None == 2.0.8

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
keepalived edge-community 2.0.11-r0 None fixed
keepalived 3.22-community 2.0.11-r0 None fixed
keepalived 3.21-community 2.0.11-r0 None fixed
keepalived 3.20-community 2.0.11-r0 None fixed
keepalived 3.19-community 2.0.11-r0 None fixed
keepalived 3.18-community 2.0.11-r0 None fixed
keepalived 3.17-community 2.0.11-r0 None fixed