RSS   Vulnerabilities for 'GKSU'   RSS

2014-09-18
 
CVE-2014-2886

CWE-264
 

 
GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situations involving an untrusted substring within this argument, as demonstrated by an untrusted filename encountered during installation of a VirtualBox extension pack.

 

 >>> Vendor: Nongnu 7 Products
Mail notification
Samizdat
CVS
Oath toolkit
GKSU
Icoutils
Zutils


Copyright 2024, cxsecurity.com

 

Back to Top