CVE-2019-18899: Apt-Cacher-NG Project Apt-Cacher-NG
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to 3.1-lp151.3.3.1.
Affected products
- Apt-Cacher-NG Project Apt-Cacher-NG: before 3.1-lp151.3.3.1 (fixed in 3.1-lp151.3.3.1)
- Opensuse Backports: version sle-15 only
Published 2020-01-23. Last modified 2026-06-17.