CVE-2018-1000532: Path Traversal
beep version 1.3 and up contains a External Control of File Name or Path vulnerability in --device option that can result in Local unprivileged user can inhibit execution of arbitrary programs by other users, allowing DoS. This attack appear to be exploitable via The system must allow local users to run beep.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000532?
CVE-2018-1000532 has a moderate severity level due to its potential to cause denial of service.
How do I fix CVE-2018-1000532?
To fix CVE-2018-1000532, update to the latest version of beep where the vulnerability has been patched.
Who is affected by CVE-2018-1000532?
Local unprivileged users on systems running beep version 1.3 and up are affected by CVE-2018-1000532.
What type of vulnerability is CVE-2018-1000532?
CVE-2018-1000532 is an External Control of File Name or Path vulnerability.
Can CVE-2018-1000532 be exploited remotely?
CVE-2018-1000532 cannot be exploited remotely as it requires local user access to the system.