CVE-2018-7738
published 2018-03-07CVE-2018-7738: In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is…
PriorityP339high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.44%
35.7th percentile
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bash-completion | < util-linux 2.31.1-0.5 (bookworm) | util-linux 2.31.1-0.5 (bookworm) |
| debian | util-linux | < util-linux 2.31.1-0.5 (bookworm) | util-linux 2.31.1-0.5 (bookworm) |
| kernel | util-linux | <= 2.31 | — |
| kernel | util-linux | >= 0 < 2.31.1-0.5 | 2.31.1-0.5 |
| kernel | util-linux | >= 0 < 2.31.1-0.5 | 2.31.1-0.5 |
| kernel | util-linux | >= 0 < 2.31.1-0.5 | 2.31.1-0.5 |
| kernel | util-linux | >= 0 < 2.31.1-0.5 | 2.31.1-0.5 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
util-linux vulnerability
vendor_ubuntu·2020-09-17
CVE-2018-7738 util-linux vulnerability
Title: util-linux vulnerability
Summary: util-linux could be made to run programs when performing bash completion.
It was discovered that the umount bash completion script shipped in
util-linux incorrectly handled certain mountpoints. If a local attacker
were able to create arbitrary mountpoints, another user could be tricked
into executing arbitrary code when attempting to run the umount command
with bash completion.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
util-linux: Shell command injection in unescaped bash-completed mount point names
vendor_redhat·2018-03-07·CVSS 7.8
CVE-2018-7738 [HIGH] CWE-78 util-linux: Shell command injection in unescaped bash-completed mount point names
util-linux: Shell command injection in unescaped bash-completed mount point names
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.
A command injection flaw was found in the way util-linux implements umount autocompletion in Bash. An attacker with the ability to mount a filesystem with custom mount points may execute arbitrary commands on behalf of the user who triggers the umount autocompletion.
Statement: This issue did not affect the versions of util-linux as shipped with Red Hat Enterprise Linux 5, 6 and 7 as t
Debian
CVE-2018-7738: bash-completion - In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain...
vendor_debian·2018·CVSS 7.8
CVE-2018-7738 [HIGH] CVE-2018-7738: bash-completion - In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain...
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-jh5x-7c5f-4c44: In util-linux before 2
ghsa_unreviewed·2022-05-13
CVE-2018-7738 [HIGH] GHSA-jh5x-7c5f-4c44: In util-linux before 2
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.
OSV
CVE-2018-7738: In util-linux before 2
osv·2018-03-07·CVSS 7.8
CVE-2018-7738 [HIGH] CVE-2018-7738: In util-linux before 2
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-7738 util-linux: Shell command injection in unescaped bash-completed mount point names
bugzilla·2018-03-07·CVSS 7.8
CVE-2018-7738 [HIGH] CVE-2018-7738 util-linux: Shell command injection in unescaped bash-completed mount point names
CVE-2018-7738 util-linux: Shell command injection in unescaped bash-completed mount point names
In util-linux before 2.32-rc1, bash-completion/umount does not correctly escape
special characters embedded in mountpoint names, which may allow an attacker to
execute arbitrary shell commands on behalf of the victim user by mounting
filesystems in specially crafted mountpoints. For the vulnerability to be
triggered, the victim user has to use autocompletion while running the
umount command.
An attacker may be able to mount filesystems with custom mountpoints by
connecting a USB device with a crafted Volume name, by using UDisks2, FUSE or
with the help of desktop environments.
Upstream issue:
https://github.com/karelzak/util-linux/issues/539
Upstream patch:
https://github.com/karelzak/util
Bugzilla
CVE-2018-7738 util-linux: Shell command injection in unescaped bash-completed mount point names [fedora-all]
bugzilla·2018-03-07·CVSS 7.8
CVE-2018-7738 [HIGH] CVE-2018-7738 util-linux: Shell command injection in unescaped bash-completed mount point names [fedora-all]
CVE-2018-7738 util-linux: Shell command injection in unescaped bash-completed mount point names [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
arXiv
Well Begun is Half Done: An Empirical Study of Exploitability & Impact of Base-Image Vulnerabilities
arxiv_fulltext·2021-12-21
Well Begun is Half Done: An Empirical Study of Exploitability & Impact of Base-Image Vulnerabilities
Well Begun is Half Done: An Empirical Study of Exploitability & Impact of Base-Image Vulnerabilities
Mubin Ul Haque2 and
M. Ali Babar 3
Centre for Research on Engineering Software Technologies (CREST)
School of Computer Science, and Engineering, The University of Adelaide, Adelaide, Australia
Cyber Security Cooperative Research Centre, Australia
[email protected], [email protected]
plain
plain
## Abstract
Container technology, (e.g., Docker) is being widely adopted for deploying software infrastructures or applications in the form of container images.
Security vulnerabilities in the container images are a primary concern for developing containerized software.
Exploitation of the vulnerabilities could result in disastrous impact, such as loss of confidentiality, in
http://www.securityfocus.com/bid/103367https://bugs.debian.org/892179https://github.com/karelzak/util-linux/commit/75f03badd7ed9f1dd951863d75e756883d3acc55https://github.com/karelzak/util-linux/issues/539https://usn.ubuntu.com/4512-1/https://www.debian.org/security/2018/dsa-4134http://www.securityfocus.com/bid/103367https://bugs.debian.org/892179https://github.com/karelzak/util-linux/commit/75f03badd7ed9f1dd951863d75e756883d3acc55https://github.com/karelzak/util-linux/issues/539https://security.netapp.com/advisory/ntap-20241213-0002/https://usn.ubuntu.com/4512-1/https://www.debian.org/security/2018/dsa-4134
2018-03-07
Published