SUSE update for util-linux



Published: 2023-11-21
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2018-7738
CWE-ID CWE-264
Exploitation vector Local
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
Subscribe
SUSE Linux Enterprise Server for SAP Applications 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15 SP2 LTSS
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15 SP1 LTSS
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing 15
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
Operating systems & Components / Operating system

SUSE CaaS Platform
Operating systems & Components / Operating system

libmount1-32bit
Operating systems & Components / Operating system package or component

libblkid1-32bit
Operating systems & Components / Operating system package or component

libblkid1-32bit-debuginfo
Operating systems & Components / Operating system package or component

libuuid1-32bit
Operating systems & Components / Operating system package or component

libuuid1-32bit-debuginfo
Operating systems & Components / Operating system package or component

libmount1-32bit-debuginfo
Operating systems & Components / Operating system package or component

util-linux-lang
Operating systems & Components / Operating system package or component

libmount-devel
Operating systems & Components / Operating system package or component

util-linux-systemd-debuginfo
Operating systems & Components / Operating system package or component

libblkid-devel
Operating systems & Components / Operating system package or component

libmount1
Operating systems & Components / Operating system package or component

libblkid1-debuginfo
Operating systems & Components / Operating system package or component

libsmartcols1-debuginfo
Operating systems & Components / Operating system package or component

util-linux-debuginfo
Operating systems & Components / Operating system package or component

libfdisk1
Operating systems & Components / Operating system package or component

libuuid1-debuginfo
Operating systems & Components / Operating system package or component

util-linux
Operating systems & Components / Operating system package or component

libsmartcols1
Operating systems & Components / Operating system package or component

uuidd-debuginfo
Operating systems & Components / Operating system package or component

uuidd
Operating systems & Components / Operating system package or component

libmount1-debuginfo
Operating systems & Components / Operating system package or component

libuuid1
Operating systems & Components / Operating system package or component

libblkid1
Operating systems & Components / Operating system package or component

util-linux-systemd-debugsource
Operating systems & Components / Operating system package or component

libfdisk1-debuginfo
Operating systems & Components / Operating system package or component

libblkid-devel-static
Operating systems & Components / Operating system package or component

libsmartcols-devel
Operating systems & Components / Operating system package or component

util-linux-debugsource
Operating systems & Components / Operating system package or component

util-linux-systemd
Operating systems & Components / Operating system package or component

libfdisk-devel
Operating systems & Components / Operating system package or component

libuuid-devel
Operating systems & Components / Operating system package or component

libuuid-devel-static
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Privilege escalation

EUVDB-ID: #VU10957

Risk: Low

CVSSv3.1: 7 [CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C]

CVE-ID: CVE-2018-7738

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to insufficient validation of shell commands that are used in the name of a mountpoint. A local attacker can embed crafted shell commands in the name of a mountpoint. If another user on the system executes the umount command along with a tab character for autocomplete, the attacker can gain elevated privileges.

Mitigation

Update the affected package util-linux to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server for SAP Applications 15: SP1 - SP2

SUSE Linux Enterprise Server 15 SP2 LTSS: 15-SP2

SUSE Linux Enterprise Server 15: SP1 - SP2

SUSE Linux Enterprise Server 15 SP1 LTSS: 15-SP1

SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS: 15-SP2

SUSE Linux Enterprise High Performance Computing 15: SP1 - SP2

SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS: 15-SP1

SUSE CaaS Platform: 4.0

libmount1-32bit: before 2.33.2-150100.4.40.1

libblkid1-32bit: before 2.33.2-150100.4.40.1

libblkid1-32bit-debuginfo: before 2.33.2-150100.4.40.1

libuuid1-32bit: before 2.33.2-150100.4.40.1

libuuid1-32bit-debuginfo: before 2.33.2-150100.4.40.1

libmount1-32bit-debuginfo: before 2.33.2-150100.4.40.1

util-linux-lang: before 2.33.2-150100.4.40.1

libmount-devel: before 2.33.2-150100.4.40.1

util-linux-systemd-debuginfo: before 2.33.2-150100.4.40.1

libblkid-devel: before 2.33.2-150100.4.40.1

libmount1: before 2.33.2-150100.4.40.1

libblkid1-debuginfo: before 2.33.2-150100.4.40.1

libsmartcols1-debuginfo: before 2.33.2-150100.4.40.1

util-linux-debuginfo: before 2.33.2-150100.4.40.1

libfdisk1: before 2.33.2-150100.4.40.1

libuuid1-debuginfo: before 2.33.2-150100.4.40.1

util-linux: before 2.33.2-150100.4.40.1

libsmartcols1: before 2.33.2-150100.4.40.1

uuidd-debuginfo: before 2.33.2-150100.4.40.1

uuidd: before 2.33.2-150100.4.40.1

libmount1-debuginfo: before 2.33.2-150100.4.40.1

libuuid1: before 2.33.2-150100.4.40.1

libblkid1: before 2.33.2-150100.4.40.1

util-linux-systemd-debugsource: before 2.33.2-150100.4.40.1

libfdisk1-debuginfo: before 2.33.2-150100.4.40.1

libblkid-devel-static: before 2.33.2-150100.4.40.1

libsmartcols-devel: before 2.33.2-150100.4.40.1

util-linux-debugsource: before 2.33.2-150100.4.40.1

util-linux-systemd: before 2.33.2-150100.4.40.1

libfdisk-devel: before 2.33.2-150100.4.40.1

libuuid-devel: before 2.33.2-150100.4.40.1

libuuid-devel-static: before 2.33.2-150100.4.40.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234512-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.



###SIDEBAR###