CVE-2014-5220

The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
References
Link Resource
https://lists.opensuse.org/opensuse-updates/2015-02/msg00069.html Mailing List Vendor Advisory
https://bugzilla.suse.com/show_bug.cgi?id=910500 Issue Tracking Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:mdadm_project:mdadm:*:*:*:*:*:*:*:*

Information

Published : 2018-06-08 10:29

Updated : 2019-07-16 05:24


NVD link : CVE-2014-5220

Mitre link : CVE-2014-5220


JSON object : View

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Advertisement

dedicated server usa

Products Affected

mdadm_project

  • mdadm

opensuse

  • opensuse