USN-5459-1
Dashboard / Vulnerabilities / USN-5459-1
USN-5459-1
Summary: cifs-utils vulnerabilities
Details: Aurélien Aptel discovered that cifs-utils invoked a shell when requesting a password. In certain environments, a local attacker could possibly use this issue to escalate privileges. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-14342) It was discovered that cifs-utils incorrectly used host credentials when mounting a krb5 CIFS file system from within a container. An attacker inside a container could possibly use this issue to obtain access to sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-20208) It was discovered that cifs-utils incorrectly handled certain command-line arguments. A local attacker could possibly use this issue to obtain root privileges. (CVE-2022-27239) It was discovered that cifs-utils incorrectly handled verbose logging. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2022-29869)
References: https://ubuntu.com/security/notices/USN-5459-1, https://ubuntu.com/security/CVE-2020-14342, https://ubuntu.com/security/CVE-2021-20208, https://ubuntu.com/security/CVE-2022-27239, https://ubuntu.com/security/CVE-2022-29869
Affected packages
Package
Name: cifs-utils
Purl: pkg:deb/ubuntu/cifs-utils@2:6.8-1ubuntu1.2?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
