Back

HIGH

mdadm: Improper sanitization of device names allows arbitrary command execution

Published Jun 8, 2018

Description

The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microfocus
Published Jun 8, 2018
Updated Aug 6, 2024
Reserved Aug 13, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 17, 2014