Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary commands via crafted filenames that inject command line arguments when Beagle launches external helper applications while indexing.
References
Link | Resource |
---|---|
http://lists.seifried.org/pipermail/security/2006-April/013163.html | Broken Link |
http://scary.beasts.org/security/CESA-2006-002.html | Third Party Advisory |
http://secunia.com/advisories/19778 | Broken Link Vendor Advisory |
http://secunia.com/advisories/19781 | Broken Link Vendor Advisory |
http://secunia.com/advisories/19897 | Broken Link Vendor Advisory |
http://www.novell.com/linux/security/advisories/2006_04_28.html | Broken Link |
http://www.osvdb.org/24938 | Broken Link |
http://www.securityfocus.com/bid/17611 | Broken Link Third Party Advisory VDB Entry |
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189282 | Issue Tracking |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26104 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2006-04-21 23:06
Updated : 2024-02-13 17:54
NVD link : CVE-2006-1865
Mitre link : CVE-2006-1865
CVE.ORG link : CVE-2006-1865
JSON object : View
Products Affected
beagle_project
- beagle
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')