Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-7738

Опубликовано: 07 мар. 2018
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kernel:util-linux:*:*:*:*:*:*:*:*
Версия до 2.31 (включая)

EPSS

Процентиль: 18%
0.00058
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.

CVSS3: 6.7
redhat
почти 8 лет назад

In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.

CVSS3: 7.8
debian
почти 8 лет назад

In util-linux before 2.32-rc1, bash-completion/umount allows local use ...

suse-cvrf
больше 7 лет назад

Security update for util-linux

suse-cvrf
больше 7 лет назад

Security update for util-linux

EPSS

Процентиль: 18%
0.00058
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

NVD-CWE-noinfo