Vulnerability Bulletins |
DSA-4134 util-linux - security update |
|
| Affected software | Debian |
|
Bjorn Bosselmann discovered that the umount bash completion fromutil-linux does not properly handle embedded shell commands in amountpoint name. An attacker with rights to mount filesystems can takeadvantage of this flaw for privilege escalation if a user (in particularroot) is tricked into using the umount completion while a speciallycrafted mount is present. More info: https://www.debian.org/security/2018/dsa-4134 |
|






