Bug 1174477 (CVE-2020-14342) - VUL-1: CVE-2020-14342: cifs-utils: Shell command injection vulnerability in mount.cifs
Summary: VUL-1: CVE-2020-14342: cifs-utils: Shell command injection vulnerability in m...
Status: RESOLVED FIXED
Alias: CVE-2020-14342
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: SUSE Samba Team
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/264209/
Whiteboard: CVSSv3.1:SUSE:CVE-2020-14342:4.4:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2020-07-24 14:59 UTC by Marcus Meissner
Modified: 2021-05-01 01:28 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 2 Aurelien Aptel 2020-09-04 09:54:28 UTC
Patch has been reviewed, CVE has been announced publicly.

All MR for the CVE are sent. They should probably be set to higher priority.
Comment 4 Robert Frohl 2020-09-04 15:24:10 UTC
public via https://wiki.samba.org/index.php/LinuxCIFS_utils
Comment 5 Swamp Workflow Management 2020-09-23 19:15:17 UTC
SUSE-SU-2020:2729-1: An update that solves one vulnerability and has one errata is now available.

Category: security (moderate)
Bug References: 1152930,1174477
CVE References: CVE-2020-14342
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Basesystem 15-SP2 (src):    cifs-utils-6.9-5.6.1
SUSE Linux Enterprise Module for Basesystem 15-SP1 (src):    cifs-utils-6.9-5.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2020-09-23 19:17:47 UTC
SUSE-SU-2020:2728-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1174477
CVE References: CVE-2020-14342
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    cifs-utils-6.9-13.11.1
SUSE Linux Enterprise Server 12-SP5 (src):    cifs-utils-6.9-13.11.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2020-09-30 04:14:01 UTC
openSUSE-SU-2020:1579-1: An update that solves one vulnerability and has one errata is now available.

Category: security (moderate)
Bug References: 1152930,1174477
CVE References: CVE-2020-14342
JIRA References: 
Sources used:
openSUSE Leap 15.1 (src):    cifs-utils-6.9-lp151.4.7.1
Comment 8 Aurelien Aptel 2020-12-21 10:15:00 UTC
closing
Comment 12 Swamp Workflow Management 2021-04-30 13:17:21 UTC
SUSE-SU-2021:1455-1: An update that solves two vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1152930,1174477,1183239,1184815
CVE References: CVE-2020-14342,CVE-2021-20208
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15 (src):    cifs-utils-6.9-3.14.1
SUSE Linux Enterprise Server 15-LTSS (src):    cifs-utils-6.9-3.14.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    cifs-utils-6.9-3.14.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    cifs-utils-6.9-3.14.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2021-05-01 01:28:22 UTC
openSUSE-SU-2021:0639-1: An update that solves two vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1152930,1174477,1183239,1184815
CVE References: CVE-2020-14342,CVE-2021-20208
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    cifs-utils-6.9-lp152.2.3.1