GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situations involving an untrusted substring within this argument, as demonstrated by an untrusted filename encountered during installation of a VirtualBox extension pack.
References
Configurations
Information
Published : 2014-09-18 03:55
Updated : 2018-12-31 03:29
NVD link : CVE-2014-2886
Mitre link : CVE-2014-2886
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
nongnu
- gksu