Loading HuntDB...

GHSA-ghcf-6h3j-46qc

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast.

Related CVEs

Key Information

GHSA ID
GHSA-ghcf-6h3j-46qc
Published
May 13, 2022 1:32 AM
Last Modified
May 13, 2022 1:32 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.