CVE-2019-18899: Apt-Cacher-NG Project Apt-Cacher-NG

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to 3.1-lp151.3.3.1.

Affected products

Published 2020-01-23. Last modified 2026-06-17.