CVE Vulnerabilities

CVE-2014-2527

Published: Aug 26, 2014 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a (double quote) character in the directory name, a different vulnerability than CVE-2014-2528.

Affected Software

Name Vendor Start Version End Version
Kdirstat Kdirstat_project 2.7.0 (including) 2.7.0 (including)
Opensuse Opensuse 13.1 (including) 13.1 (including)
K4dirstat Ubuntu artful *
K4dirstat Ubuntu precise *
K4dirstat Ubuntu quantal *
K4dirstat Ubuntu saucy *
K4dirstat Ubuntu trusty *
K4dirstat Ubuntu utopic *
K4dirstat Ubuntu vivid *
K4dirstat Ubuntu wily *
K4dirstat Ubuntu yakkety *
K4dirstat Ubuntu zesty *
Kdirstat Ubuntu lucid *

References