SB2020093008 - OpenSUSE Linux update for cifs-utils 



SB2020093008 - OpenSUSE Linux update for cifs-utils

Published: September 30, 2020 Updated: June 2, 2022

Security Bulletin ID SB2020093008
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) OS Command Injection (CVE-ID: CVE-2020-14342)

The vulnerability allows a local authenticated user to execute arbitrary code.

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.


Remediation

Install update from vendor's website.