Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-7738

Опубликовано: 07 мар. 2018
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.

A command injection flaw was found in the way util-linux implements umount autocompletion in Bash. An attacker with the ability to mount a filesystem with custom mount points may execute arbitrary commands on behalf of the user who triggers the umount autocompletion.

Отчет

This issue did not affect the versions of util-linux as shipped with Red Hat Enterprise Linux 5, 6 and 7 as they did not include support for umount autocompletion.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5util-linuxNot affected
Red Hat Enterprise Linux 6util-linux-ngNot affected
Red Hat Enterprise Linux 7util-linuxNot affected
Red Hat Enterprise Linux 8util-linuxNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=1552641util-linux: Shell command injection in unescaped bash-completed mount point names

EPSS

Процентиль: 18%
0.00058
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.

CVSS3: 7.8
nvd
почти 8 лет назад

In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.

CVSS3: 7.8
debian
почти 8 лет назад

In util-linux before 2.32-rc1, bash-completion/umount allows local use ...

suse-cvrf
больше 7 лет назад

Security update for util-linux

suse-cvrf
больше 7 лет назад

Security update for util-linux

EPSS

Процентиль: 18%
0.00058
Низкий

6.7 Medium

CVSS3