CVE-2018-12562
Summary
| CVE | CVE-2018-12562 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-19 05:29:00 UTC |
| Updated | 2018-08-10 18:05:00 UTC |
| Description | An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary. The shell evaluates wildcards (such as in an injected string:/home/../tmp/* string). |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cantata Project | Cantata | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Remove internal Samba shre mounting code, this had some privilege esc… · CDrummond/cantata@afc4f83 · GitHub | MISC | github.com | Patch, Technical Description |
| oss-security - cantata: cantata-mounter D-Bus service local privilege escalation and other security issues | MISC | www.openwall.com | Mailing List, Technical Description |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.