9
CVSSv2

CVE-2014-8170

Published: 26/09/2017 Updated: 13/02/2023
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate malicious users to execute arbitrary commands via a ; (semicolon) in an input string.

Vulnerable Product Search on Vulmon Subscribe to Product

ovirt ovirt-node 3.0.0-474-gb852fd7

Vendor Advisories

ovirt_safe_delete_config in ovirtfunctionspy and other unspecified locations in ovirt-node 300-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate attackers to execute arbitrary commands via a ; (semicolon) in an input string ...