CVE-2011-2651: High severity kiwi vulnerability
Published Aug 23, 2011
·Updated
Unspecified vulnerability in the file browser in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename.
Affected Software
2 affected components
Marcus Schafer Kiwi<=3.74.1
Novell Suse Studio Onsite=1.1
Event History
Aug 23, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2651?
CVE-2011-2651 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2011-2651?
To fix CVE-2011-2651, upgrade to Kiwi version 3.74.2 or later and ensure you are using Suse Studio Onsite version 1.1.4 or higher.
3
What software is affected by CVE-2011-2651?
CVE-2011-2651 affects Kiwi versions up to 3.74.1 and Suse Studio Onsite version 1.1.
4
Can CVE-2011-2651 be exploited remotely?
Yes, CVE-2011-2651 can be exploited remotely by attackers using a crafted filename.
5
Who is responsible for addressing CVE-2011-2651?
Software vendors Marcus Schafer for Kiwi and Novell for Suse Studio are responsible for addressing CVE-2011-2651.