CVE-2011-4192: High severity SUSE kiwi vulnerability
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwioemtitle of .profile."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4192?
CVE-2011-4192 is considered a critical vulnerability as it allows attackers to execute arbitrary commands.
How do I fix CVE-2011-4192?
To fix CVE-2011-4192, upgrade to kiwi version 4.85.1 or later, and update SUSE Studio Onsite and SUSE Studio Extension for System z to version 1.2.1 or later.
Which software is affected by CVE-2011-4192?
CVE-2011-4192 affects Suse Kiwi versions up to 4.85, SUSE Studio Onsite version 1.2, and SUSE Studio Extension for System z version 1.2.
What are the potential impacts of CVE-2011-4192?
The potential impacts of CVE-2011-4192 include unauthorized command execution, which can lead to system compromise.
Is there a workaround for CVE-2011-4192?
There is no known workaround for CVE-2011-4192; the only solution is to apply the security updates.