CVE-2011-4195: High severity SUSE Studio Extension for System z vulnerability
kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in an image name.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4195?
CVE-2011-4195 has been classified with a high severity due to the potential for arbitrary command execution.
How do I fix CVE-2011-4195?
To fix CVE-2011-4195, upgrade kiwi to version 4.98.05 or later, and apply the latest updates for SUSE Studio Onsite 1.2 and SUSE Studio Extension for System z.
What versions of software are affected by CVE-2011-4195?
CVE-2011-4195 affects kiwi versions below 4.98.05, SUSE Studio Onsite 1.2, and SUSE Studio Extension for System z 1.2.
What kind of attacks can CVE-2011-4195 enable?
CVE-2011-4195 can enable attackers to execute arbitrary commands on the affected systems.
Is CVE-2011-4195 a client-side or server-side vulnerability?
CVE-2011-4195 is primarily a server-side vulnerability due to its impact on server applications that process image names.