GParted before 0.15.0 allows local users to execute arbitrary commands with root privileges via shell metacharacters in a crafted filesystem label.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2014/Dec/77 | Exploit Mailing List Third Party Advisory |
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2014-12-19 15:59
Updated : 2021-05-14 19:57
NVD link : CVE-2014-7208
Mitre link : CVE-2014-7208
CVE.ORG link : CVE-2014-7208
JSON object : View
Products Affected
gparted
- gparted
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')