python-gnupg CVE-2014-1928 Incomplete Fix Unspecified Remote Command Injection Vulnerability
BID:65548
Info
python-gnupg CVE-2014-1928 Incomplete Fix Unspecified Remote Command Injection Vulnerability
| Bugtraq ID: | 65548 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1928 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2014 12:00AM |
| Updated: | Apr 13 2015 09:53PM |
| Credit: | Matthew Daley |
| Vulnerable: |
Vinay Sajip python-gnupg 0.3.5 Vinay Sajip python-gnupg 0.3.4 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Vinay Sajip python-gnupg 0.3.6 |
Discussion
python-gnupg CVE-2014-1928 Incomplete Fix Unspecified Remote Command Injection Vulnerability
python-gnupg is prone to a remote command-injection vulnerability.
An attacker may leverage this issue to execute arbitrary commands in the context of the affected application.
Versions prior to python-gnupg 0.3.6 are vulnerable.
Note: This issue exists due to an incomplete fix for CVE-2013-7323 (identified in BID 65540 - python-gnupg CVE-2013-7323 Unspecified Remote Command Injection Vulnerability).
python-gnupg is prone to a remote command-injection vulnerability.
An attacker may leverage this issue to execute arbitrary commands in the context of the affected application.
Versions prior to python-gnupg 0.3.6 are vulnerable.
Note: This issue exists due to an incomplete fix for CVE-2013-7323 (identified in BID 65540 - python-gnupg CVE-2013-7323 Unspecified Remote Command Injection Vulnerability).
Solution / Fix
python-gnupg CVE-2014-1928 Incomplete Fix Unspecified Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.