PT-2011-3403 · Canonical · Language-Selector
Romain Perier
+1
·
Publicado
2011-05-03
·
Atualizado
2017-08-17
·
CVE-2011-1842
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
language-selector versions prior to 0.6.7
Description
The issue concerns a lack of validation for arguments passed to certain functions, allowing local users to potentially gain privileges through the use of shell metacharacters in string arguments. This is related to the
SetSystemDefaultLangEnv and SetSystemDefaultLanguageEnv functions in the D-Bus backend.Recommendations
For versions prior to 0.6.7, update to version 0.6.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the
SetSystemDefaultLangEnv and SetSystemDefaultLanguageEnv functions until a patch is available.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Language-Selector