PT-2014-1903 · Kde+1 · Kdirstat+1
Published
2014-06-15
·
Updated
2018-10-30
·
CVE-2014-2527
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
KDirStat versions prior to 2.7.5
Description
The issue allows remote attackers to execute arbitrary commands, potentially leading to a breach of confidentiality, integrity, and availability of protected information. In KDirStat 2.7.0, the
kcleanup.cpp file does not properly quote strings when deleting a directory. This can be exploited by including a " (double quote) character in the directory name, enabling the execution of arbitrary commands.Recommendations
For versions prior to 2.7.5, update to version 2.7.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
kcleanup.cpp function until a patch is available. Avoid using directory names that include special characters, such as ", in the affected API endpoint until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kdirstat
Suse