CVE-2018-20106

Publication date

2019-03-15 20:00:00

Family

microfocus

State

PUBLISHED

Description

In yast2-printer up to and including version 4.0.2 the SMB printer settings dont escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast.