PT-2011-3403 · Canonical · Language-Selector
Romain Perier
+1
·
Published
2011-05-03
·
Updated
2017-08-17
·
CVE-2011-1842
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
language-selector versions prior to 0.6.7
Description
The issue concerns a lack of validation for arguments passed to certain functions, allowing local users to potentially gain privileges through the use of shell metacharacters in string arguments. This is related to the
SetSystemDefaultLangEnv and SetSystemDefaultLanguageEnv functions in the D-Bus backend.Recommendations
For versions prior to 0.6.7, update to version 0.6.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the
SetSystemDefaultLangEnv and SetSystemDefaultLanguageEnv functions until a patch is available.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Language-Selector