Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia 6 MGASA-2018-0402 Moderate: Mgetty Command Injection

mageia
Calendar Grey October 19, 2018
Dist Mageia Esm H88
MGASA-2018-0402 - Updated mgetty packages fix security vulnerabilities Publication date: 19 Oct 2018
Updated mgetty packages fix security vulnerabilities: The function do_activate() did not properly sanitize shell metacharacters to prevent command injection (CVE-2018-16741)

Summary

Updated mgetty packages fix security vulnerabilities:
The function do_activate() did not properly sanitize shell metacharactersto prevent command injection (CVE-2018-16741).
Stack-based buffer overflow that could have been triggered via a command-line parameter (CVE-2018-16742).
The command-line parameter username wsa passed unsanitized to strcpy(), which could have caused a stack-based buffer overflow (CVE-2018-16743).
The mail_to parameter was not sanitized, leading to command injection if untrusted input reached reach it (CVE-2018-16744).
The mail_to parameter was not sanitized, leading to a buffer overflow if long untrusted input reached it (CVE-2018-16745).

References

- https://bugs.mageia.org/show_bug.cgi?id=23567

- - https://www.cve.org/CVERecord?id=CVE-2018-16741

- https://www.cve.org/CVERecord?id=CVE-2018-16742

- https://www.cve.org/CVERecord?id=CVE-2018-16743

- https://www.cve.org/CVERecord?id=CVE-2018-16744

- https://www.cve.org/CVERecord?id=CVE-2018-16745

Resolution

SRPMS

- 6/core/mgetty-1.1.37-1.1.mga6

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 19 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0402.html
Type: security
CVE: CVE-2018-16741, CVE-2018-16742, CVE-2018-16743, CVE-2018-16744, CVE-2018-16745

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here