CVE-2018-12561 log

Severity Medium
Remote No
Type Access restriction bypass
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additional mount options such as file_mode= by manipulating (for example) the domain parameter of the samba URL.
Group Package Affected Fixed Severity Status Ticket
AVG-721 cantata 2.3.1-1 2.3.1-2 High Fixed
Date Advisory Group Package Severity Type
20 Jun 2018 ASA-201806-12 AVG-721 cantata High multiple issues