PT-2014-1903 · Kde+1 · Kdirstat+1

Published

2014-06-15

·

Updated

2018-10-30

·

CVE-2014-2527

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions KDirStat versions prior to 2.7.5
Description The issue allows remote attackers to execute arbitrary commands, potentially leading to a breach of confidentiality, integrity, and availability of protected information. In KDirStat 2.7.0, the kcleanup.cpp file does not properly quote strings when deleting a directory. This can be exploited by including a " (double quote) character in the directory name, enabling the execution of arbitrary commands.
Recommendations For versions prior to 2.7.5, update to version 2.7.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the kcleanup.cpp function until a patch is available. Avoid using directory names that include special characters, such as ", in the affected API endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09769
CVE-2014-2527
SUSE-SU-2014_0930-1

Affected Products

Kdirstat
Suse