KDE Workspace Arbitrary Command Execution Vulnerability
BID:70904
Info
KDE Workspace Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 70904 |
| Class: | Design Error |
| CVE: |
CVE-2014-8651 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2014 12:00AM |
| Updated: | Feb 02 2016 08:08PM |
| Credit: | David Edmundson |
| Vulnerable: |
KDE Kde-Workspace 4.10.5 Gentoo Linux |
| Not Vulnerable: |
KDE Kde-Workspace 4.14.3 |
Discussion
KDE Workspace Arbitrary Command Execution Vulnerability
KDE Workspace is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker can execute arbitrary commands with the privileges of the affected application.
KDE Workspace prior to 4.14.3 are vulnerable.
KDE Workspace is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker can execute arbitrary commands with the privileges of the affected application.
KDE Workspace prior to 4.14.3 are vulnerable.
Exploit / POC
KDE Workspace Arbitrary Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
KDE Workspace Arbitrary Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information
Solution:
Updates are available. Please see the references or vendor advisory for more information