Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-5220

Опубликовано: 17 дек. 2014
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5mdadmNot affected
Red Hat Enterprise Linux 6mdadmNot affected
Red Hat Enterprise Linux 7mdadmNot affected
Red Hat Enterprise Linux 8mdadmNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1589839mdadm: Improper sanitization of device names allows arbitrary command execution

EPSS

Процентиль: 37%
0.00158
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.

CVSS3: 7.8
nvd
больше 7 лет назад

The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.

CVSS3: 7.8
debian
больше 7 лет назад

The mdcheck script of the mdadm package for openSUSE 13.2 prior to ver ...

CVSS3: 7.8
github
больше 3 лет назад

The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.

EPSS

Процентиль: 37%
0.00158
Низкий

6.6 Medium

CVSS3