Security Advisory

CVE-2018-20106

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-03-15 20:00:00
Last updated 2024-09-16 17:23:19
Assigner microfocus
CVSS score 6.5
State PUBLISHED

Description

In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast.