PT-2012-3797 · Gajim · Gajim

David Black

·

Published

2012-08-28

·

Updated

2013-04-19

·

CVE-2012-2085

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Gajim versions prior to 0.15
Description The issue allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an href attribute, specifically through the exec command function in common/helpers.py.
Recommendations For versions prior to 0.15, update to version 0.15 or later to resolve the issue.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2085
DSA-2453-1
DSA-2453-2

Affected Products

Gajim