The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
References
Link | Resource |
---|---|
https://lists.opensuse.org/opensuse-updates/2015-02/msg00069.html | Mailing List Vendor Advisory |
https://bugzilla.suse.com/show_bug.cgi?id=910500 | Issue Tracking Vendor Advisory |
Information
Published : 2018-06-08 10:29
Updated : 2019-07-16 05:24
NVD link : CVE-2014-5220
Mitre link : CVE-2014-5220
JSON object : View
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Products Affected
mdadm_project
- mdadm
opensuse
- opensuse