First published: Mon Mar 17 2014(Updated: )
Adrian Panasiuk discovered that the KDirStat (KDE Directory Statistics) tool did not correctly escape quotes when deleting a directory permanently. Attempting to use KDirStat to permanently delete a directory that has a malicious name could result in arbitrary command execution. The original report is regarding single quotes. Testing with the Fedora revealed the issue there was with double quotes. Original report: <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741659">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741659</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDirStat | =2.7.0 | |
SUSE Linux | =13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2527 has a high severity level due to the potential for arbitrary command execution.
To fix CVE-2014-2527, update KDirStat to the latest version that has addressed this vulnerability.
CVE-2014-2527 affects KDirStat version 2.7.0 and openSUSE version 13.1.
CVE-2014-2527 facilitates an attack that could lead to arbitrary command execution when deleting directories.
CVE-2014-2527 was discovered by Adrian Panasiuk.