The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local users to execute arbitrary commands with root privileges via shell metacharacters in the xmlPath argument.
References
Link | Resource |
---|---|
https://gpgtools.org/releases/gpgsuite/2015.08/release-notes.html | Release Notes Vendor Advisory |
https://bierbaumer.net/security/cve-2014-4677/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2017-02-22 08:59
Updated : 2018-05-02 08:25
NVD link : CVE-2014-4677
Mitre link : CVE-2014-4677
JSON object : View
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Products Affected
gpgtools
- libmacgpg