Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary commands via crafted filenames that inject command line arguments when Beagle launches external helper applications while indexing.
References
| Link | Resource |
|---|---|
| http://lists.seifried.org/pipermail/security/2006-April/013163.html | Broken Link |
| http://scary.beasts.org/security/CESA-2006-002.html | Third Party Advisory |
| http://secunia.com/advisories/19778 | Broken Link Vendor Advisory |
| http://secunia.com/advisories/19781 | Broken Link Vendor Advisory |
| http://secunia.com/advisories/19897 | Broken Link Vendor Advisory |
| http://www.novell.com/linux/security/advisories/2006_04_28.html | Broken Link |
| http://www.osvdb.org/24938 | Broken Link |
| http://www.securityfocus.com/bid/17611 | Broken Link Third Party Advisory VDB Entry |
| https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189282 | Issue Tracking |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/26104 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2006-04-21 23:06
Updated : 2024-02-13 17:54
NVD link : CVE-2006-1865
Mitre link : CVE-2006-1865
CVE.ORG link : CVE-2006-1865
JSON object : View
Products Affected
beagle_project
- beagle
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
