First published: Wed May 10 2017(Updated: )
smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/smb4k | <2.0.1 | 2.0.1 |
Smb4K | <=2.0.0 | |
Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8849 is classified as a critical vulnerability due to its potential for local users to gain root privileges.
To fix CVE-2017-8849, upgrade to version 2.0.1 or later of smb4k.
CVE-2017-8849 affects local users of smb4k versions prior to 2.0.1.
Exploiting CVE-2017-8849 allows local users to execute arbitrary commands with root privileges.
CVE-2017-8849 impacts systems running vulnerable versions of smb4k, including certain versions on Debian and Red Hat.