CVE Vulnerabilities

CVE-2021-23556

Published: Mar 17, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The package guake before 3.8.5 are vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_command and execute_command_by_uuid methods via the d-bus interface, which makes it possible for a malicious user to run an arbitrary command via the d-bus method. Note: Exploitation requires the user to have installed another malicious program that will be able to send dbus signals or run terminal commands.

Affected Software

NameVendorStart VersionEnd Version
GuakeGuake-project*3.8.5 (excluding)
GuakeUbuntubionic*
GuakeUbuntufocal*
GuakeUbuntuimpish*
GuakeUbuntukinetic*
GuakeUbuntulunar*
GuakeUbuntumantic*
GuakeUbuntuoracular*
GuakeUbuntuplucky*
GuakeUbuntutrusty*
GuakeUbuntuxenial*

References