GParted CVE-2014-7208 OS Command Injection Vulnerability
BID:71739
Info
GParted CVE-2014-7208 OS Command Injection Vulnerability
| Bugtraq ID: | 71739 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7208 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2014 12:00AM |
| Updated: | Dec 18 2014 12:00AM |
| Credit: | W. Ettlinger of SEC Consult Vulnerability Lab. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
GParted CVE-2014-7208 OS Command Injection Vulnerability
GParted is prone to an OS command-injection vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary OS commands in the context of the affected application.
GParted 0.14.1 versions prior to 0.15.0 are vulnerable.
GParted is prone to an OS command-injection vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary OS commands in the context of the affected application.
GParted 0.14.1 versions prior to 0.15.0 are vulnerable.
Exploit / POC
GParted CVE-2014-7208 OS Command Injection Vulnerability
Attackers can exploit this issue using browser or readily available tools.
Attackers can exploit this issue using browser or readily available tools.
Solution / Fix
GParted CVE-2014-7208 OS Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GParted CVE-2014-7208 OS Command Injection Vulnerability
References:
References: