{"id":"MGASA-2017-0171","summary":"Updated smb4k packages fix security vulnerability","details":"Smb4k contains a logic flaw in which mount helper binary does not properly\nverify the mount command it is being asked to run. This allows calling any\nother binary as root since the mount helper is typically installed as suid\n(CVE-2017-8849).\n","modified":"2026-04-16T06:23:11.292840763Z","published":"2017-06-14T13:50:35Z","upstream":["CVE-2017-8849"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2017-0171.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=20844"},{"type":"ADVISORY","url":"https://www.kde.org/info/security/advisory-20170510-2.txt"}],"affected":[{"package":{"name":"smb4k","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/smb4k?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.3-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0171.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}