CVE-2016-1602: Suse Linux Enterprise Desktop

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root).

Affected products

  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Linux Enterprise Server: version 12 only
  • Suse Suse Linux Enterprise Server: version 12 only

Published 2017-03-23. Last modified 2026-06-17.