CVE-2018-15912 Information
Feb 14, 2021
cve
Description
An issue was discovered in manjaro-update-system.sh in manjaro-system 20180716-1 on Manjaro Linux. A local attacker can install or remove arbitrary packages and package repositories potentially containing hooks with arbitrary code which will automatically be run as root or remove packages vital to the system.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://gitlab.manjaro.org/packages/core/manjaro-system/commit/8208b8a https://lists.manjaro.org/pipermail/manjaro-security/2018-August/000785.html
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: