CVE-2014-2528
26.08.2014, 14:55
kcleanup.cpp in KDirStat 2.7.3 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a ' (single quote) character in the directory name, a different vulnerability than CVE-2014-2527.Enginsight
| Vendor | Product | Version |
|---|---|---|
| kdirstat_project | kdirstat | 2.7.3 |
| opensuse | opensuse | 13.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| k4dirstat |
| ||||||||||||||||||||||||||||||
| kdirstat |
|
References