| Vulnerability Name: | CVE-2017-8849 (CCN-126180) | ||||||||||||||||||||||||||||||||||||||||||||
| Assigned: | 2017-05-10 | ||||||||||||||||||||||||||||||||||||||||||||
| Published: | 2017-05-10 | ||||||||||||||||||||||||||||||||||||||||||||
| Updated: | 2019-03-18 | ||||||||||||||||||||||||||||||||||||||||||||
| Summary: | smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service. | ||||||||||||||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2017-8849 Source: DEBIAN Type: Third Party Advisory DSA-3951 Source: CCN Type: oss-sec Mailing List, Wed, 10 May 2017 12:05:04 +0200 generic kde LPE Source: MLIST Type: Exploit, Mailing List, Patch, Third Party Advisory [oss-security] 20170510 generic kde LPE Source: BID Type: Third Party Advisory, VDB Entry 98690 Source: CCN Type: BID-98690 Smb4K CVE-2017-8849 Local Privilege Escalation Vulnerability Source: BID Type: Third Party Advisory, VDB Entry 98737 Source: CCN Type: BID-98737 Juju CVE-2017-8849 Local Privilege Escalation Vulnerability Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory, VDB Entry https://bugzilla.redhat.com/show_bug.cgi?id=1449656 Source: CONFIRM Type: Patch, Third Party Advisory https://cgit.kde.org/smb4k.git/commit/?id=71554140bdaede27b95dbe4c9b5a028a83c83cce Source: CONFIRM Type: Patch, Third Party Advisory https://cgit.kde.org/smb4k.git/commit/?id=a90289b0962663bc1d247bbbd31b9e65b2ca000e Source: XF Type: UNKNOWN smb4k-cve20178849-priv-esc(126180) Source: GENTOO Type: Third Party Advisory GLSA-201705-14 Source: CCN Type: Smb4K Web site Advanced Network Neighborhood Browser and Samba Share Mounting Utility Source: EXPLOIT-DB Type: Exploit, Third Party Advisory, VDB Entry 42053 Source: CONFIRM Type: Third Party Advisory https://www.kde.org/info/security/advisory-20170510-2.txt | ||||||||||||||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||||||||||||||