Bug#892179: code execution in bash-completion for umount

2018-03-06 Thread Salvatore Bonaccorso
Control: reassign -1 src:util-linux 2.29.2-1 Control: tags -1 + upstream fixed-upstream Hi Björn Thanks for reporting the issue! On Tue, Mar 06, 2018 at 02:44:39PM +0100, Björn Bosselmann wrote: > Package: bash-completion > Version: 1:2.1-4.3 > Severity: grave > Tags: security > > Hi, > > when

Bug#892179: code execution in bash-completion for umount

2018-03-06 Thread Björn Bosselmann
Package: bash-completion Version: 1:2.1-4.3 Severity: grave Tags: security Hi, when bash-completion is installed, it uses /usr/share/bash-completion/completions/umount from umount package to provide autocompletion. This script does not escape mount paths correctly, so it allows a local user with