6.8
CVSSv2

CVE-2014-2528

Published: 26/08/2014 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

kcleanup.cpp in KDirStat 2.7.3 does not properly quote strings when deleting a directory, which allows remote malicious users to execute arbitrary commands via a ' (single quote) character in the directory name, a different vulnerability than CVE-2014-2527.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kdirstat project kdirstat 2.7.3

opensuse opensuse 13.1

Vendor Advisories

Debian Bug report logs - #741659 k4dirstat: Apostrophes not properly escaped in 'rm -rf' invocation Package: k4dirstat; Maintainer for k4dirstat is Jerome Robert <jeromerobert@gmxcom>; Source for k4dirstat is src:k4dirstat (PTS, buildd, popcon) Reported by: Adrian Panasiuk <perserwrita@riseupnet> Date: Sat, 15 Mar ...