CVE-2018-20106: SMB printer settings don't escape characters in passwords properly
In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20106?
CVE-2018-20106 is considered a high severity vulnerability due to its potential for remote code execution as root.
How do I fix CVE-2018-20106?
To fix CVE-2018-20106, upgrade yast2-printer to version 4.0.3 or later.
What versions of yast2-printer are affected by CVE-2018-20106?
yast2-printer versions up to and including 4.0.2 are affected by CVE-2018-20106.
Can CVE-2018-20106 be exploited remotely?
CVE-2018-20106 requires local user interaction, making it less likely to be exploited remotely.
What are the implications of CVE-2018-20106 for system security?
The implications of CVE-2018-20106 include the potential for an attacker to execute arbitrary code with root privileges if they successfully trick the root user into entering a malicious password.