CVE-2018-1000532 Information

Description

beep version 1.3 and up contains a External Control of File Name or Path vulnerability in –device option that can result in Local unprivileged user can inhibit execution of arbitrary programs by other users allowing DoS. This attack appear to be exploitable via The system must allow local users to run beep.

CVSS Vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Reference

https://github.com/johnath/beep/issues/11issuecomment-379514298

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

4.7

Share on: