CVE-2018-0643: Canonical Ubuntu Linux

Medium severity, CVSS 6.6. EPSS: 0.5% chance of exploitation in the next 30 days.

Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only
  • Orcamo Online Receipt Computer Advantage: version 4.8.0 only

Published 2018-09-07. Last modified 2026-06-17.