6.8
CVSSv2

CVE-2014-2886

Published: 18/09/2014 Updated: 31/12/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows malicious users to execute arbitrary commands in certain situations involving an untrusted substring within this argument, as demonstrated by an untrusted filename encountered during installation of a VirtualBox extension pack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nongnu gksu 2.0.2