check_smart prior to 6.9.1 allows unintended drive access by an unprivileged user because it only checks for a substring match of a device path (the /dev/bus substring and a number), aka an unanchored regular expression.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
check smart project check smart |