QID 670862
Date Published: 2021-12-02
QID 670862: EulerOS Security Update for cifs-utils (EulerOS-SA-2021-2575)
The SMB/CIFS protocol is a standard file sharing protocol widely deployed on Microsoft Windows machines. This package contains tools for mounting shares on Linux using the SMB/CIFS protocol. The tools in this package work in conjunction with support in the kernel to allow one to mount a SMB/CIFS share onto a client and use it as if it were a standard Linux file system.
Security Fix(es):
A flaw was found in cifs-utils. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.(CVE-2021-20208)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An arbitrary attacker may exploit this vulnerability to compromise the system.
CVEs related to QID 670862
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EulerOS-SA-2021-2575 | EulerOS V2.0SP3 |
|