PT-2017-14513 · None+1 · Notify-Send+2

Published

2017-11-08

·

Updated

2019-04-30

·

CVE-2017-16667

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions backintime versions prior to 1.1.24
Description The issue arises from improper escaping/quoting of file paths used as arguments to the 'notify-send' command. This could allow an attacker to craft an unreadable file with a specific name to run arbitrary shell commands within an os.system call in qt4/plugins/notifyplugin.py.
Recommendations For versions prior to 1.1.24, update to version 1.1.24 or later to resolve the issue. As a temporary workaround, consider restricting access to the 'notify-send' command or the notifyplugin.py module to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16667
MGASA-2018-0059

Affected Products

Back In Time
Notify-Send
Qt4