Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12562

Опубликовано: 19 июн. 2018
Источник: debian

Описание

An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary. The shell evaluates wildcards (such as in an injected string:/home/../tmp/* string).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cantatafixed2.3.0.ds1-2package

Примечания

  • https://www.openwall.com/lists/oss-security/2018/06/18/1

  • The daemon code is part of cantata since version 2.0.0 and it is built

  • by default in versions 2.3.0 and 2.3.1. Before 2.3.0 it was only built

  • if `-DENABLE_REMOTE_DEVICES=ON` was passed to the cmake invocation.

  • 2.3.0.ds1-2 disables the cantata-mounter.

  • https://github.com/CDrummond/cantata/commit/afc4f8315d3e96574925fb530a7004cc9e6ce3d3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary. The shell evaluates wildcards (such as in an injected string:/home/../tmp/* string).

CVSS3: 9.8
nvd
больше 7 лет назад

An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary. The shell evaluates wildcards (such as in an injected string:/home/../tmp/* string).

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary. The shell evaluates wildcards (such as in an injected string:/home/../tmp/* string).