GParted before 0.15.0 allows local users to execute arbitrary commands with root privileges via shell metacharacters in a crafted filesystem label.
References
| Link | Resource |
|---|---|
| http://seclists.org/fulldisclosure/2014/Dec/77 | Exploit Mailing List Third Party Advisory |
| http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html | Third Party Advisory |
Configurations
Information
Published : 2014-12-19 15:59
Updated : 2021-05-14 19:57
NVD link : CVE-2014-7208
Mitre link : CVE-2014-7208
JSON object : View
Products Affected
gparted
- gparted
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
