CVE-2018-17336Use of Externally-Controlled Format String in Udisks

Severity
7.8HIGHNVD
EPSS
0.3%
top 42.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 22
Latest updateMay 14

Description

UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as demonstrated by %d or %n substrings.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

Also affects: Ubuntu Linux 18.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wc77-2q7w-jfm4: UDisks 22022-05-14
CVEList
CVE-2018-17336: UDisks 22018-09-22
OSV
CVE-2018-17336: UDisks 22018-09-22

📋Vendor Advisories

3
Ubuntu
UDisks vulnerability2018-09-26
Red Hat
udisks: Format string vulnerability in udisks_log in udiskslogging.c2018-09-22
Debian
CVE-2018-17336: udisks2 - UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c,...2018

💬Community

3
Bugzilla
CVE-2018-17336 udisks: Format string vulnerability in udisks_log in udiskslogging.c2018-09-25
Bugzilla
CVE-2018-17336 udisks2: udisks: Format string vulnerability in udisks_log in udiskslogging.c [fedora-all]2018-09-25
Bugzilla
CVE-2018-17336 udisks: Format string vulnerability in udisks_log in udiskslogging.c [fedora-all]2018-09-25
CVE-2018-17336 — Freedesktop Udisks vulnerability | cvebase