CVE-2011-2649: Input Validation
Published Aug 23, 2011
·Updated
Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.
Affected Software
2 affected components
Marcus Schafer Kiwi<=3.74.1
Novell Suse Studio Onsite=1.1
Event History
Aug 23, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2649?
CVE-2011-2649 is considered a high severity vulnerability due to the potential for arbitrary command execution.
2
How do I fix CVE-2011-2649?
To fix CVE-2011-2649, upgrade Kiwi to version 3.74.2 or later and ensure you are using Suse Studio Onsite version 1.1.4 or later.
3
What software is affected by CVE-2011-2649?
CVE-2011-2649 affects Kiwi versions prior to 3.74.2 and Suse Studio Onsite version 1.1.
4
What type of attack does CVE-2011-2649 facilitate?
CVE-2011-2649 allows attackers to execute arbitrary commands through the use of shell metacharacters.
5
Who is the vendor associated with CVE-2011-2649?
CVE-2011-2649 is associated with Marcus Schafer's Kiwi and Novell's Suse Studio Onsite.