Spoofing attack in osc - CVE-2019-3685
Published: August 12, 2019
Vulnerability identifier: #VU20061
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3685
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of untrusted TLS certificates. A remote attacker can create a specially crafted TLS certificate and perform Man-in-the-Middle (MitM) attack.
Affected software
osc
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Opensuse
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Opensuse
How to mitigate CVE-2019-3685
Install updates from vendor's website.
osc - addressed in versions 0.165.4, 0.182.0-15.12.1