USN-6711-1: CRM shell vulnerability
Published Mar 25, 2024
·Updated
Vincent Berg discovered that CRM shell incorrectly handled certain commands. An local attacker could possibly use this issue to execute arbitrary code via shell code injection to the crm history commandline.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/crmsh<4.2.0-2ubuntu1.1
4.2.0-2ubuntu1.1
Ubuntu Ubuntu=20.04
Event History
Mar 25, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6711-1?
USN-6711-1 is classified as a high severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix USN-6711-1?
To fix USN-6711-1, update the crmsh package to version 4.2.0-2ubuntu1.1 or later.
3
What systems are affected by USN-6711-1?
USN-6711-1 affects Ubuntu 20.04 systems with an unpatched version of the crmsh package.
4
What exploit method is used in USN-6711-1?
USN-6711-1 can be exploited by local attackers using shell code injection via the crm history command line.
5
Who discovered the vulnerability noted in USN-6711-1?
The vulnerability in USN-6711-1 was discovered by Vincent Berg.