SB2018062624 - Path traversal in beep



SB2018062624 - Path traversal in beep

Published: June 26, 2018 Updated: August 8, 2020

Security Bulletin ID SB2018062624
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Path traversal (CVE-ID: CVE-2018-1000532)

The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.

beep version 1.3 and up contains a External Control of File Name or Path vulnerability in --device option that can result in Local unprivileged user can inhibit execution of arbitrary programs by other users, allowing DoS. This attack appear to be exploitable via The system must allow local users to run beep.


Remediation

Install update from vendor's website.