Description
In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-12676 | In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast. |
References
| Link | Providers |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1114853 |
|
History
No history.
Status: PUBLISHED
Assigner: microfocus
Published:
Updated: 2024-09-16T17:23:19.129Z
Reserved: 2018-12-12T00:00:00.000Z
Link: CVE-2018-20106
No data.
Status : Modified
Published: 2019-03-15T20:29:00.730
Modified: 2024-11-21T04:00:53.397
Link: CVE-2018-20106
No data.
OpenCVE Enrichment
No data.
EUVD