Beveiligingsadvies

CVE-2018-20106

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-03-15 20:00:00
Laatst bijgewerkt 2024-09-16 17:23:19
Toegewezen door microfocus
CVSS-score 6.5
Status PUBLISHED

Beschrijving

In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast.