Bugzilla – Bug 1156495
VUL-1: CVE-2019-18862: mailutils: setuid binary might allow local privilege escalation in url mode
Last modified: 2019-11-12 15:40:07 UTC
CVE-2019-18862 maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-18862 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-18862.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18862 https://git.savannah.gnu.org/cgit/mailutils.git/tree/NEWS
does not affect openSUSE: "disabled suid/sgid program dotlock and maidag"
This is an autogenerated message for OBS integration: This bug (1156495) was mentioned in https://build.opensuse.org/request/show/747751 Factory / mailutils