First published: Wed Sep 26 2018(Updated: )
It was discovered that UDisks incorrectly handled format strings when logging. A local attacker could possibly use this issue to cause a denial of service or obtain sensitive information.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/udisks2 | <2.7.6-3ubuntu0.2 | 2.7.6-3ubuntu0.2 |
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this UDisks vulnerability is CVE-2018-17336.
The UDisks vulnerability can potentially cause a denial of service or allow an attacker to obtain sensitive information on the affected system.
The udisks2 package version 2.7.6-3ubuntu0.2 on Ubuntu 18.04 is affected by this vulnerability.
To fix this vulnerability, you should update the udisks2 package to version 2.7.6-3ubuntu0.2 or higher.
More information about this UDisks vulnerability can be found on the Ubuntu Security Notices website or the CVE-2018-17336 page.