6.8
CVSSv2

CVE-2012-2085

Published: 28/08/2012 Updated: 19/04/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The exec_command function in common/helpers.py in Gajim prior to 0.15 allows user-assisted remote malicious users to execute arbitrary commands via shell metacharacters in an href attribute.

Vulnerable Product Search on Vulmon Subscribe to Product

gajim gajim 0.11.4

gajim gajim 0.12.5

gajim gajim 0.13

gajim gajim 0.13.1

gajim gajim 0.10.1

gajim gajim 0.11.2

gajim gajim 0.11.3

gajim gajim 0.12.3

gajim gajim 0.12.4

gajim gajim 0.10

gajim gajim 0.11

gajim gajim 0.1

gajim gajim

gajim gajim 0.12

gajim gajim 0.13.2

gajim gajim 0.13.3

gajim gajim 0.11.1

gajim gajim 0.14.3

gajim gajim 0.12.1

gajim gajim 0.12.2

gajim gajim 0.13.4

gajim gajim 0.14

gajim gajim 0.14.2

gajim gajim 0.14.1

Vendor Advisories

Debian Bug report logs - #668038 gajim code execution and sql injection Package: gajim; Maintainer for gajim is Debian XMPP Maintainers <pkg-xmpp-devel@listsaliothdebianorg>; Source for gajim is src:gajim (PTS, buildd, popcon) Reported by: "Thijs Kinkhorst" <thijs@debianorg> Date: Sun, 8 Apr 2012 13:51:02 UTC S ...
Debian Bug report logs - #668710 gajim: CVE-2012-2093 insecure temporary file creation in LaTeX support Package: gajim; Maintainer for gajim is Debian XMPP Maintainers <pkg-xmpp-devel@listsaliothdebianorg>; Source for gajim is src:gajim (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Sat, 14 ...
Several vulnerabilities have been discovered in Gajim, a feature-rich Jabber client The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2012-1987 Gajim is not properly sanitizing input before passing it to shell commands An attacker can use this flaw to execute arbitrary code on behalf of the victi ...