Bugzilla – Bug 1174477
VUL-1: CVE-2020-14342: cifs-utils: Shell command injection vulnerability in mount.cifs
Last modified: 2021-05-01 01:28:22 UTC
I have made internal repos with v3 patch from the upstream bugzilla for all affected products. I will make a MR once the patch is reviewed by Pavel upstream (or possibly update it before). https://build.suse.de/project/show/home:aaptel:cifs-utils-bso14442-sle12 https://build.suse.de/project/show/home:aaptel:cifs-utils-bso14442-sle12sp1 https://build.suse.de/project/show/home:aaptel:cifs-utils-bso14442-sle12sp2 https://build.suse.de/project/show/home:aaptel:cifs-utils-bso14442-sle12sp4 https://build.suse.de/project/show/home:aaptel:cifs-utils-bso14442-sle15 https://build.suse.de/project/show/home:aaptel:cifs-utils-bso14442-sle15sp1
Patch has been reviewed, CVE has been announced publicly. All MR for the CVE are sent. They should probably be set to higher priority.
public via https://wiki.samba.org/index.php/LinuxCIFS_utils
SUSE-SU-2020:2729-1: An update that solves one vulnerability and has one errata is now available. Category: security (moderate) Bug References: 1152930,1174477 CVE References: CVE-2020-14342 JIRA References: Sources used: SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): cifs-utils-6.9-5.6.1 SUSE Linux Enterprise Module for Basesystem 15-SP1 (src): cifs-utils-6.9-5.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2020:2728-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1174477 CVE References: CVE-2020-14342 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): cifs-utils-6.9-13.11.1 SUSE Linux Enterprise Server 12-SP5 (src): cifs-utils-6.9-13.11.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2020:1579-1: An update that solves one vulnerability and has one errata is now available. Category: security (moderate) Bug References: 1152930,1174477 CVE References: CVE-2020-14342 JIRA References: Sources used: openSUSE Leap 15.1 (src): cifs-utils-6.9-lp151.4.7.1
closing
SUSE-SU-2021:1455-1: An update that solves two vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1152930,1174477,1183239,1184815 CVE References: CVE-2020-14342,CVE-2021-20208 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15 (src): cifs-utils-6.9-3.14.1 SUSE Linux Enterprise Server 15-LTSS (src): cifs-utils-6.9-3.14.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): cifs-utils-6.9-3.14.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): cifs-utils-6.9-3.14.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:0639-1: An update that solves two vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1152930,1174477,1183239,1184815 CVE References: CVE-2020-14342,CVE-2021-20208 JIRA References: Sources used: openSUSE Leap 15.2 (src): cifs-utils-6.9-lp152.2.3.1