Udisks CVE-2018-17336 Local Format String Vulnerability
BID:107537
Info
Udisks CVE-2018-17336 Local Format String Vulnerability
| Bugtraq ID: | 107537 |
| Class: | Design Error |
| CVE: |
CVE-2018-17336 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 22 2018 12:00AM |
| Updated: | Sep 22 2018 12:00AM |
| Credit: | oxagast |
| Vulnerable: |
Ubuntu Ubuntu Linux 18.04 LTS Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 freedesktop udisks 2.8 |
| Not Vulnerable: | |
Discussion
Udisks CVE-2018-17336 Local Format String Vulnerability
Udisks is prone to a local format-string vulnerability.
A local attacker may exploit this issue to crash the affected application, resulting in a denial-of-service condition. The attacker may also be able to execute arbitrary code within the context of the application, but this has not been confirmed.
UDisks version 2.8.0 is vulnerable; other versions may also be affected.
Udisks is prone to a local format-string vulnerability.
A local attacker may exploit this issue to crash the affected application, resulting in a denial-of-service condition. The attacker may also be able to execute arbitrary code within the context of the application, but this has not been confirmed.
UDisks version 2.8.0 is vulnerable; other versions may also be affected.
Exploit / POC
Udisks CVE-2018-17336 Local Format String Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].