Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-20106

Опубликовано: 15 мар. 2019
Источник: nvd
CVSS3: 6.5
CVSS3: 8.1
CVSS2: 9.3
EPSS Низкий

Описание

In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:opensuse:yast2-printer:*:*:*:*:*:*:*:*
Версия до 4.0.2 (включая)

EPSS

Процентиль: 34%
0.00135
Низкий

6.5 Medium

CVSS3

8.1 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-78
CWE-20

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast.

EPSS

Процентиль: 34%
0.00135
Низкий

6.5 Medium

CVSS3

8.1 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-78
CWE-20