PT-2014-2165 · Suse · Suse Studio Extension For System Z+2

Published

2014-04-16

·

Updated

2014-04-17

·

CVE-2011-4192

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions kiwi versions prior to 4.85.1 SUSE Studio Onsite versions prior to 1.2.1 SUSE Studio Extension for System z versions prior to 1.2.1
Description The issue allows attackers to execute arbitrary commands. This can be demonstrated by using double quotes in kiwi oemtitle of .profile.
Recommendations For kiwi versions prior to 4.85.1, update to version 4.85.1 or later. For SUSE Studio Onsite versions prior to 1.2.1, update to version 1.2.1 or later. For SUSE Studio Extension for System z versions prior to 1.2.1, update to version 1.2.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-4192

Affected Products

Suse Studio Extension For System Z
Suse Studio Onsite
Kiwi