blkid 'blkid.c' Local Command Injection Vulnerability
BID:71327
Info
blkid 'blkid.c' Local Command Injection Vulnerability
| Bugtraq ID: | 71327 |
| Class: | Design Error |
| CVE: |
CVE-2014-9114 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 27 2014 12:00AM |
| Updated: | Dec 20 2016 01:07AM |
| Credit: | Sebastian Krahmer |
| Vulnerable: |
Linux kernel Gentoo Linux blkid blkid 0 |
| Not Vulnerable: | |
Discussion
blkid 'blkid.c' Local Command Injection Vulnerability
blkid is prone to a local command-injection vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with root privileges. Successful exploits may compromise the affected computer.
blkid is prone to a local command-injection vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with root privileges. Successful exploits may compromise the affected computer.
Exploit / POC
blkid 'blkid.c' Local Command Injection Vulnerability
Attackers can use standard commands to exploit this issue.
Attackers can use standard commands to exploit this issue.
Solution / Fix
blkid 'blkid.c' Local Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
blkid 'blkid.c' Local Command Injection Vulnerability
References:
References:
- blkid command injection (SecLists.Org)
- blkid Homepage (blkid )
- Bug 1168485 - (CVE-2014-9114) CVE-2014-9114 util-linux: command injection flaw i (Red Hat Bugzilla)
- libblkid: care about unsafe chars in cache (Sebastian Krahmer)