CVE-2018-12562
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary. The shell evaluates wildcards (such as in an injected string:/home/../tmp/* string).
Affected (1)
Products: Cantata Project: Cantata
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.3.1 |
References (4)
Source: cve@mitre.org
Mailing ListTechnical Description
Source: cve@mitre.org
PatchTechnical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListTechnical Description
Source: af854a3a-2127-422b-91ae-364da2661108
PatchTechnical Description
Timeline
No history available yet.