MGASA-2017-0171

Source
https://advisories.mageia.org/MGASA-2017-0171.html
Import Source
https://advisories.mageia.org/MGASA-2017-0171.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2017-0171
Related
Published
2017-06-14T13:50:35Z
Modified
2017-06-14T13:37:19Z
Summary
Updated smb4k packages fix security vulnerability
Details

Smb4k contains a logic flaw in which mount helper binary does not properly verify the mount command it is being asked to run. This allows calling any other binary as root since the mount helper is typically installed as suid (CVE-2017-8849).

References
Credits

Affected packages

Mageia:5 / smb4k

Package

Name
smb4k
Purl
pkg:rpm/mageia/smb4k?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.3-1.mga5

Ecosystem specific

{
    "section": "core"
}