USN-4512-1

Source
https://ubuntu.com/security/notices/USN-4512-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4512-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-4512-1
Related
Published
2020-09-17T11:31:17.123140Z
Modified
2020-09-17T11:31:17.123140Z
Summary
util-linux vulnerability
Details

It was discovered that the umount bash completion script shipped in util-linux incorrectly handled certain mountpoints. If a local attacker were able to create arbitrary mountpoints, another user could be tricked into executing arbitrary code when attempting to run the umount command with bash completion.

References

Affected packages

Ubuntu:18.04:LTS / util-linux

Package

Name
util-linux
Purl
pkg:deb/ubuntu/util-linux@2.31.1-0.4ubuntu3.7?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.31.1-0.4ubuntu3.7

Affected versions

2.*

2.30.1-0ubuntu4
2.30.2-0.1ubuntu1
2.30.2-0.1ubuntu2
2.30.2-0.1ubuntu3
2.31.1-0.4ubuntu2
2.31.1-0.4ubuntu3
2.31.1-0.4ubuntu3.1
2.31.1-0.4ubuntu3.2
2.31.1-0.4ubuntu3.3
2.31.1-0.4ubuntu3.4
2.31.1-0.4ubuntu3.5
2.31.1-0.4ubuntu3.6

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1:2.31.1-0.4ubuntu3.7",
            "binary_name": "bsdutils"
        },
        {
            "binary_version": "1:2.31.1-0.4ubuntu3.7",
            "binary_name": "bsdutils-dbgsym"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "fdisk"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "fdisk-dbgsym"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "fdisk-udeb"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libblkid-dev"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libblkid1"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libblkid1-dbgsym"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libblkid1-udeb"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libfdisk-dev"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libfdisk1"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libfdisk1-dbgsym"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libfdisk1-udeb"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libmount-dev"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libmount1"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libmount1-dbgsym"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libmount1-udeb"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libsmartcols-dev"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libsmartcols1"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libsmartcols1-dbgsym"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libsmartcols1-udeb"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libuuid1"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libuuid1-dbgsym"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "libuuid1-udeb"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "mount"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "mount-dbgsym"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "rfkill"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "rfkill-dbgsym"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "setpriv"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "setpriv-dbgsym"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "util-linux"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "util-linux-dbgsym"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "util-linux-locales"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "util-linux-udeb"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "uuid-dev"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "uuid-runtime"
        },
        {
            "binary_version": "2.31.1-0.4ubuntu3.7",
            "binary_name": "uuid-runtime-dbgsym"
        }
    ]
}