Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-14342

Опубликовано: 09 сент. 2020
Источник: ubuntu
Приоритет: low
CVSS2: 4.4
CVSS3: 4.4

Описание

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.

РелизСтатусПримечание
bionic

released

2:6.8-1ubuntu1.2
devel

released

2:6.11-0ubuntu1
esm-infra-legacy/trusty

released

2:6.0-1ubuntu2+esm1
esm-infra/bionic

released

2:6.8-1ubuntu1.2
esm-infra/focal

released

2:6.9-1ubuntu0.2
esm-infra/xenial

released

2:6.4-1ubuntu1.1+esm1
focal

released

2:6.9-1ubuntu0.2
groovy

released

2:6.11-0ubuntu1
hirsute

released

2:6.11-0ubuntu1
impish

released

2:6.11-0ubuntu1

Показывать по

4.4 Medium

CVSS2

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
больше 5 лет назад

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.

CVSS3: 4.4
nvd
больше 5 лет назад

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.

CVSS3: 7
msrc
больше 5 лет назад

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission such as via sudo rules could use this flaw to escalate their privileges.

CVSS3: 4.4
debian
больше 5 лет назад

It was found that cifs-utils' mount.cifs was invoking a shell when req ...

suse-cvrf
больше 5 лет назад

Security update for cifs-utils

4.4 Medium

CVSS2

4.4 Medium

CVSS3