4.6
CVSSv2

CVE-2011-4349

Published: 10/12/2011 Updated: 12/12/2011
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in (1) cd-mapping-db.c and (2) cd-device-db.c in colord prior to 0.1.15 allow local users to execute arbitrary SQL commands via vectors related to color devices and (a) device id, (b) property, or (c) profile id.

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop colord 0.1.3

freedesktop colord 0.1.2

freedesktop colord 0.1.1

freedesktop colord 0.1.0

freedesktop colord 0.1.11

freedesktop colord 0.1.10

freedesktop colord 0.1.9

freedesktop colord 0.1.8

freedesktop colord 0.1.13

freedesktop colord 0.1.6

freedesktop colord 0.1.4

freedesktop colord

freedesktop colord 0.1.12

freedesktop colord 0.1.7

freedesktop colord 0.1.5

Vendor Advisories

Debian Bug report logs - #650021 CVE-2011-4349: SQL injection Package: src:colord; Maintainer for src:colord is Christopher James Halse Rogers <raof@ubuntucom>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 25 Nov 2011 17:27:01 UTC Severity: grave Tags: security Fixed in version colord/0115-1 Done: ...
colord could be made to modify databases ...