Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Robin Broda

#35611of 56,330
7.8Total CVSS
Vulnerabilities · 1
PT-2018-13284
7.8
2018-08-29
Manjaro · Manjaro-System · CVE-2018-15912
**Name of the Vulnerable Software and Affected Versions** manjaro-system version 20180716-1 **Description** A local attacker can exploit an issue in the manjaro-update-system.sh script to install or remove arbitrary packages and package repositories. These repositories can contain hooks with arbitrary code that will automatically be run as root. Additionally, an attacker can remove vital system packages. **Recommendations** For manjaro-system version 20180716-1, consider restricting access to the package management system to prevent unauthorized installation or removal of packages until a fix is available. As a temporary workaround, monitor system package changes closely to detect and mitigate potential attacks.