TROYANOSYVIRUS
Back to CVEs

CVE-2018-7738

N/A

Description

In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.

CVE Details

CVSS v3.1 ScoreN/A
Published3/7/2018
Last Modified12/13/2024
Sourcenvd
Honeypot Sightings0

Affected Products

kernel:util-linux

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.