Vulnerability Bulletins

DSA-4134 util-linux - security update

   
Affected software Debian
 
Bjorn Bosselmann discovered that the umount bash completion fromutil-linux does not properly handle embedded shell commands in amountpoint name. An attacker with rights to mount filesystems can takeadvantage of this flaw for privilege escalation if a user (in particularroot) is tricked into using the umount completion while a speciallycrafted mount is present.

More info:

https://www.debian.org/security/2018/dsa-4134