Описание
Security update for util-linux
This update for util-linux fixes the following issues:
This non-security issue was fixed:
- CVE-2018-7738: bash-completion/umount allowed local users to gain privileges by embedding shell commands in a mountpoint name, which was mishandled during a umount command by a different user (bsc#1084300).
These non-security issues were fixed:
- Fixed crash loop in lscpu (bsc#1072947).
- Fixed possible segfault of umount -a
- Fixed mount -a on NFS bind mounts (bsc#1080740).
- Fixed lsblk on NVMe (bsc#1078662).
Список пакетов
SUSE Linux Enterprise Desktop 12 SP3
libblkid1-2.29.2-3.12.1
libblkid1-32bit-2.29.2-3.12.1
libfdisk1-2.29.2-3.12.1
libmount1-2.29.2-3.12.1
libmount1-32bit-2.29.2-3.12.1
libsmartcols1-2.29.2-3.12.1
libuuid-devel-2.29.2-3.12.1
libuuid1-2.29.2-3.12.1
libuuid1-32bit-2.29.2-3.12.1
python-libmount-2.29.2-3.12.1
util-linux-2.29.2-3.12.1
util-linux-lang-2.29.2-3.12.1
util-linux-systemd-2.29.2-3.12.1
uuidd-2.29.2-3.12.1
SUSE Linux Enterprise Server 12 SP3
libblkid1-2.29.2-3.12.1
libblkid1-32bit-2.29.2-3.12.1
libfdisk1-2.29.2-3.12.1
libmount1-2.29.2-3.12.1
libmount1-32bit-2.29.2-3.12.1
libsmartcols1-2.29.2-3.12.1
libuuid1-2.29.2-3.12.1
libuuid1-32bit-2.29.2-3.12.1
python-libmount-2.29.2-3.12.1
util-linux-2.29.2-3.12.1
util-linux-lang-2.29.2-3.12.1
util-linux-systemd-2.29.2-3.12.1
uuidd-2.29.2-3.12.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
libblkid1-2.29.2-3.12.1
libblkid1-32bit-2.29.2-3.12.1
libfdisk1-2.29.2-3.12.1
libmount1-2.29.2-3.12.1
libmount1-32bit-2.29.2-3.12.1
libsmartcols1-2.29.2-3.12.1
libuuid1-2.29.2-3.12.1
libuuid1-32bit-2.29.2-3.12.1
python-libmount-2.29.2-3.12.1
util-linux-2.29.2-3.12.1
util-linux-lang-2.29.2-3.12.1
util-linux-systemd-2.29.2-3.12.1
uuidd-2.29.2-3.12.1
SUSE Linux Enterprise Software Development Kit 12 SP3
libblkid-devel-2.29.2-3.12.1
libmount-devel-2.29.2-3.12.1
libsmartcols-devel-2.29.2-3.12.1
libuuid-devel-2.29.2-3.12.1
SUSE Linux Enterprise Workstation Extension 12 SP3
libuuid-devel-2.29.2-3.12.1
Ссылки
- Link for SUSE-SU-2018:3926-1
- E-Mail link for SUSE-SU-2018:3926-1
- SUSE Security Ratings
- SUSE Bug 1072947
- SUSE Bug 1078662
- SUSE Bug 1080740
- SUSE Bug 1084300
- SUSE CVE CVE-2018-7738 page
Описание
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.
Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP3:libblkid1-2.29.2-3.12.1
SUSE Linux Enterprise Desktop 12 SP3:libblkid1-32bit-2.29.2-3.12.1
SUSE Linux Enterprise Desktop 12 SP3:libfdisk1-2.29.2-3.12.1
SUSE Linux Enterprise Desktop 12 SP3:libmount1-2.29.2-3.12.1
Ссылки
- CVE-2018-7738
- SUSE Bug 1080740
- SUSE Bug 1084300
- SUSE Bug 1213865