7.5
CVSSv2

CVE-2011-3180

Published: 16/04/2014 Updated: 17/04/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

kiwi prior to 4.98.08, as used in SUSE Studio Onsite 1.2 prior to 1.2.1 and SUSE Studio Extension for System z 1.2 prior to 1.2.1, allows malicious users to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

suse kiwi

suse studio onsite 1.2

suse studio extension for system z 1.2