Candidate: CVE-2017-8849 PublicDate: 2017-05-17 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8849 http://www.openwall.com/lists/oss-security/2017/05/10/3 Description: smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/smb4k/+bug/1689768 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_smb4k: upstream: https://commits.kde.org/smb4k/71554140bdaede27b95dbe4c9b5a028a83c83cce (1.2.3) upstream: https://commits.kde.org/smb4k/a90289b0962663bc1d247bbbd31b9e65b2ca000e (2.0.0) upstream_smb4k: released (1.2.1-2, 2.0.1) precise/esm_smb4k: DNE trusty_smb4k: ignored (reached end-of-life) trusty/esm_smb4k: DNE (trusty was needed) vivid/stable-phone-overlay_smb4k: DNE vivid/ubuntu-core_smb4k: DNE xenial_smb4k: ignored (end of standard support, was needed) yakkety_smb4k: ignored (reached end-of-life) zesty_smb4k: ignored (reached end-of-life) artful_smb4k: ignored (reached end-of-life) bionic_smb4k: not-affected (2.1.0-1) cosmic_smb4k: not-affected (2.1.0-1) disco_smb4k: not-affected (2.1.0-1) eoan_smb4k: not-affected (2.1.0-1) focal_smb4k: not-affected (2.1.0-1) groovy_smb4k: not-affected (2.1.0-1) hirsute_smb4k: not-affected (2.1.0-1) impish_smb4k: not-affected (2.1.0-1) jammy_smb4k: not-affected (2.1.0-1) devel_smb4k: not-affected (2.1.0-1)