Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:2728-1

Опубликовано: 23 сент. 2020
Источник: suse-cvrf

Описание

Security update for cifs-utils

This update for cifs-utils fixes the following issues:

  • CVE-2020-14342: Fixed a shell command injection vulnerability in mount.cifs (bsc#1174477).

Список пакетов

Image SLES12-SP4-Azure-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP4-EC2-HVM-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP4-GCE-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP4-OCI-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP4-SAP-Azure
cifs-utils-6.9-13.11.1
Image SLES12-SP4-SAP-Azure-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
cifs-utils-6.9-13.11.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
cifs-utils-6.9-13.11.1
Image SLES12-SP4-SAP-EC2-HVM
cifs-utils-6.9-13.11.1
Image SLES12-SP4-SAP-EC2-HVM-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP4-SAP-GCE
cifs-utils-6.9-13.11.1
Image SLES12-SP4-SAP-GCE-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP4-SAP-OCI-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP5-Azure-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP5-Azure-Basic-On-Demand
cifs-utils-6.9-13.11.1
Image SLES12-SP5-Azure-HPC-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP5-Azure-HPC-On-Demand
cifs-utils-6.9-13.11.1
Image SLES12-SP5-Azure-SAP-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP5-Azure-SAP-On-Demand
cifs-utils-6.9-13.11.1
Image SLES12-SP5-Azure-Standard-On-Demand
cifs-utils-6.9-13.11.1
Image SLES12-SP5-EC2-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP5-EC2-ECS-On-Demand
cifs-utils-6.9-13.11.1
Image SLES12-SP5-EC2-On-Demand
cifs-utils-6.9-13.11.1
Image SLES12-SP5-EC2-SAP-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP5-EC2-SAP-On-Demand
cifs-utils-6.9-13.11.1
Image SLES12-SP5-GCE-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP5-GCE-On-Demand
cifs-utils-6.9-13.11.1
Image SLES12-SP5-GCE-SAP-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP5-GCE-SAP-On-Demand
cifs-utils-6.9-13.11.1
Image SLES12-SP5-OCI-BYOS-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
cifs-utils-6.9-13.11.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
cifs-utils-6.9-13.11.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
cifs-utils-6.9-13.11.1
SUSE Linux Enterprise Server 12 SP5
cifs-utils-6.9-13.11.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
cifs-utils-6.9-13.11.1
SUSE Linux Enterprise Software Development Kit 12 SP5
cifs-utils-devel-6.9-13.11.1

Описание

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:cifs-utils-6.9-13.11.1
Image SLES12-SP4-EC2-HVM-BYOS:cifs-utils-6.9-13.11.1
Image SLES12-SP4-GCE-BYOS:cifs-utils-6.9-13.11.1
Image SLES12-SP4-OCI-BYOS:cifs-utils-6.9-13.11.1

Ссылки