Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7787

Опубликовано: 23 дек. 2016
Источник: debian

Описание

A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kde-cli-toolsfixed4:5.8.0-1package
kde-runtimefixed4:16.08.3-2package
kde-runtimeno-dsajessiepackage
kde-runtimenot-affectedwheezypackage
kdesudoremovedpackage
kdesudono-dsastretchpackage
kdesudono-dsajessiepackage
kdesudonot-affectedwheezypackage

Примечания

  • https://www.kde.org/info/security/advisory-20160930-1.txt

  • https://github.com/KDE/kde-cli-tools/commit/5eda179a099ba68a20dc21dc0da63e85a565a171

  • For kde-cli-tools fixed in 5.7.5 upstream

  • kde-runtime's affected binary is /usr/lib/kde4/libexec/kdesu-distrib/kdesu

  • kdesudo's affected binary is /usr/bin/kdesudo

Связанные уязвимости

CVSS3: 4.9
ubuntu
около 9 лет назад

A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.

CVSS3: 4.9
nvd
около 9 лет назад

A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.

CVSS3: 4.9
github
больше 3 лет назад

A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.