CVE-2018-9246
Summary
| CVE | CVE-2018-9246 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-08 01:29:00 UTC |
| Updated | 2018-08-01 16:00:00 UTC |
| Description | The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the create(), run_file(), backup(), or restore() function. The vulnerability allows unauthorized users to execute code with the same privileges as the running application. |
Risk And Classification
Problem Types: CWE-116
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ledgersmb | Ledgersmb | All | All | All | All |
| Application | Pgobject-util-dbadmin Project | Pgobject-util-dbadmin | All | All | All | All |
| Application | Pgobject-util-dbadmin Project | Pgobject-util-dbadmin | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [ledgersmb-announce] Security announcement for CVE-2018-9246 / PGObject::Util::DBAdmin | CONFIRM | archive.ledgersmb.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.