CVE-2015-5349
11.04.2016, 21:59
The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.
Vendor | Product | Version |
---|---|---|
apache | ldap_studio | 0.6.0 |
apache | ldap_studio | 0.7.0 |
apache | ldap_studio | 0.8.0 |
apache | ldap_studio | 0.8.1 |
apache | directory_studio | 1.0.0 |
apache | directory_studio | 1.0.1 |
apache | directory_studio | 1.1.0 |
apache | directory_studio | 1.1.0:rc1 |
apache | directory_studio | 1.1.0:rc2 |
apache | directory_studio | 1.2.0 |
apache | directory_studio | 1.2.0:rc1 |
apache | directory_studio | 1.3.0 |
apache | directory_studio | 1.3.0:rc1 |
apache | directory_studio | 1.4.0 |
apache | directory_studio | 1.5.0 |
apache | directory_studio | 1.5.1 |
apache | directory_studio | 1.5.2 |
apache | directory_studio | 1.5.3 |
apache | directory_studio | 2.0.0:milestone1 |
apache | directory_studio | 2.0.0:milestone2 |
apache | directory_studio | 2.0.0:milestone3 |
apache | directory_studio | 2.0.0:milestone4 |
apache | directory_studio | 2.0.0:milestone5 |
apache | directory_studio | 2.0.0:milestone6 |
apache | directory_studio | 2.0.0:milestone7 |
apache | directory_studio | 2.0.0:milestone8 |
apache | directory_studio | 2.0.0:milestone9 |
𝑥
= Vulnerable software versions

Debian Releases
References