Advisories ยป MGASA-2020-0376

Updated cifs-utils packages fix security vulnerability

Publication date: 27 Sep 2020
Modification date: 27 Sep 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-14342

Description

The mount.cifs utility has a shell injection issue where one can embed shell
commands via the username mount option. Those commands will be run via popen()
in the context of the user calling mount (CVE-2020-14342).
                

References

SRPMS

7/core