PT-2018-3086 · Juniper Networks+5 · Junos+5

Bjorn Bosselmann

·

Published

2018-03-06

·

Updated

2024-12-13

·

CVE-2018-7738

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JunOS version (affected versions not specified) util-linux versions prior to 2.32-rc1
Description The issue exists due to insufficient input validation in the srxpfe process of JunOS, allowing a remote attacker to cause a denial of service. In util-linux, local users can gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command. This can be demonstrated by logging in as root, entering umount, and then using a tab character for autocompletion.
Recommendations For JunOS, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For util-linux versions prior to 2.32-rc1, update to version 2.32-rc1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the umount command to minimize the risk of exploitation. Avoid using the umount command with autocompletion, especially when logged in as root, until the issue is resolved.

Exploit

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1600
BDU:2019-03803
CVE-2018-7738
DSA-4134-1
ECHO-A45D-041F-2636
MGASA-2018-0237
OPENSUSE-SU-2018_2203-1
OPENSUSE-SU-2018_2205-1
OPENSUSE-SU-2023_4372-1
SUSE-SU-2018:2066-1
SUSE-SU-2018:2071-1
SUSE-SU-2018:3926-1
SUSE-SU-2018_2066-1
SUSE-SU-2018_2071-1
SUSE-SU-2018_3926-1
SUSE-SU-2019:0390-1
SUSE-SU-2019_0390-1
SUSE-SU-2023:3268-1
SUSE-SU-2023:4372-1
SUSE-SU-2023:4512-1
SUSE-SU-2023_3268-1
SUSE-SU-2023_4512-1
USN-4512-1

Affected Products

Alt Linux
Debian
Junos
Suse
Ubuntu
Util-Linux