7.5
CVSSv2

CVE-2014-8990

Published: 05/12/2014 Updated: 01/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

default-rsyncssh.lua in Lsyncd 2.1.5 and previous versions allows remote malicious users to execute arbitrary commands via shell metacharacters in a filename.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 7.0

fedoraproject fedora 19

fedoraproject fedora 20

lsyncd project lsyncd

Vendor Advisories

Debian Bug report logs - #767227 lsyncd: CVE-2014-8990: Crash and/or code execution on `, $, " in file names Package: lsyncd; Maintainer for lsyncd is Jan Dittberner <jandd@debianorg>; Source for lsyncd is src:lsyncd (PTS, buildd, popcon) Reported by: "creshal" <creshal@sayakaadtaoat> Date: Wed, 29 Oct 2014 13:15 ...