PT-2017-14513 · None+1 · Notify-Send+2

Publicado

2017-11-08

·

Atualizado

2019-04-30

·

CVE-2017-16667

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions backintime versions prior to 1.1.24
Description The issue arises from improper escaping/quoting of file paths used as arguments to the 'notify-send' command. This could allow an attacker to craft an unreadable file with a specific name to run arbitrary shell commands within an os.system call in qt4/plugins/notifyplugin.py.
Recommendations For versions prior to 1.1.24, update to version 1.1.24 or later to resolve the issue. As a temporary workaround, consider restricting access to the 'notify-send' command or the notifyplugin.py module to minimize the risk of exploitation.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-16667
MGASA-2018-0059

Produtos afetados

Back In Time
Notify-Send
Qt4