Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-2886

Опубликовано: 18 сент. 2014
Источник: debian

Описание

GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situations involving an untrusted substring within this argument, as demonstrated by an untrusted filename encountered during installation of a VirtualBox extension pack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gksuremovedpackage
gksuignoredstretchpackage
gksuignoredjessiepackage
gksuno-dsawheezypackage
gksuno-dsasqueezepackage

Примечания

  • https://community.rapid7.com/community/metasploit/blog/2014/07/07/virtualbox-filename-command-execution-via-gksu

  • In Debian libgksu installs two alternatives gconf-defaults.libgksu-sudo

  • and gconf-defaults.libgksu-su, where the gconf-defaults.libgksu-su is

  • enabled (in auto mode).

Связанные уязвимости

ubuntu
больше 11 лет назад

GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situations involving an untrusted substring within this argument, as demonstrated by an untrusted filename encountered during installation of a VirtualBox extension pack.

nvd
больше 11 лет назад

GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situations involving an untrusted substring within this argument, as demonstrated by an untrusted filename encountered during installation of a VirtualBox extension pack.

github
больше 3 лет назад

GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situations involving an untrusted substring within this argument, as demonstrated by an untrusted filename encountered during installation of a VirtualBox extension pack.