Vulnerabilities (CVE)

Filtered by vendor Opensuse Subscribe
Filtered by product Yast2-printer
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20106 1 Opensuse 1 Yast2-printer 2024-11-21 9.3 HIGH 6.5 MEDIUM
In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast.