Vulnerability Description
smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smb4K Project | Smb4K | <= 2.0.0 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://www.debian.org/security/2017/dsa-3951Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/05/10/3ExploitMailing ListPatch
- http://www.securityfocus.com/bid/98690Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/98737Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1449656Issue TrackingPatchThird Party Advisory
- https://cgit.kde.org/smb4k.git/commit/?id=71554140bdaede27b95dbe4c9b5a028a83c83cPatchThird Party Advisory
- https://cgit.kde.org/smb4k.git/commit/?id=a90289b0962663bc1d247bbbd31b9e65b2ca00PatchThird Party Advisory
- https://security.gentoo.org/glsa/201705-14Third Party Advisory
- https://www.exploit-db.com/exploits/42053/ExploitThird Party AdvisoryVDB Entry
- https://www.kde.org/info/security/advisory-20170510-2.txtThird Party Advisory
- http://www.debian.org/security/2017/dsa-3951Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/05/10/3ExploitMailing ListPatch
- http://www.securityfocus.com/bid/98690Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/98737Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1449656Issue TrackingPatchThird Party Advisory
FAQ
What is CVE-2017-8849?
CVE-2017-8849 is a vulnerability with a CVSS score of 7.8 (HIGH). smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service.
How severe is CVE-2017-8849?
CVE-2017-8849 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-8849?
Check the references section above for vendor advisories and patch information. Affected products include: Smb4K Project Smb4K, Debian Debian Linux.