First published: Tue Aug 26 2014(Updated: )
kcleanup.cpp in KDirStat 2.7.3 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a ' (single quote) character in the directory name, a different vulnerability than CVE-2014-2527.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDirStat | =2.7.3 | |
SUSE Linux | =13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2528 is considered a high severity vulnerability due to the potential for remote command execution.
To fix CVE-2014-2528, users should upgrade KDirStat to version 2.7.4 or later, which addresses the quoting issue.
CVE-2014-2528 affects KDirStat version 2.7.3 and openSUSE 13.1.
CVE-2014-2528 enables remote attackers to execute arbitrary commands by exploiting unquoted strings in directory names.
CVE-2014-2528 is a different vulnerability from CVE-2014-2527, each with its own exploitation method.