Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-17336

Опубликовано: 22 сент. 2018
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as demonstrated by %d or %n substrings.

An uncontrolled format string vulnerability has been discovered in udisks when it mounts a filesystem with a malformed label. A local attacker may use this flaw to leak memory, make the udisks service crash, or cause other unspecified effects.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2storagedNot affected
Red Hat Enterprise Linux 6udisksWill not fix
Red Hat Enterprise Linux 8udisks2Not affected
Red Hat Enterprise Linux 7udisks2FixedRHSA-2019:217806.08.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-134
https://bugzilla.redhat.com/show_bug.cgi?id=1632828udisks: Format string vulnerability in udisks_log in udiskslogging.c

EPSS

Процентиль: 56%
0.00344
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as demonstrated by %d or %n substrings.

CVSS3: 7.8
nvd
больше 7 лет назад

UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as demonstrated by %d or %n substrings.

CVSS3: 7.8
debian
больше 7 лет назад

UDisks 2.8.0 has a format string vulnerability in udisks_log in udisks ...

suse-cvrf
больше 7 лет назад

Security update for udisks2

suse-cvrf
больше 7 лет назад

Security update for udisks2

EPSS

Процентиль: 56%
0.00344
Низкий

7.5 High

CVSS3