CVE-2014-5220: Command Injection
Published Jun 8, 2018
·Updated
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
Affected Software
2 affected components
openSUSE openSUSE=13.2
Mdadm Project Mdadm<3.3.3
Event History
Jun 8, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is CVE-2014-5220?
CVE-2014-5220 is a vulnerability in the mdcheck script of the mdadm package for openSUSE 13.2.
2
How does CVE-2014-5220 impact openSUSE 13.2?
CVE-2014-5220 allows local attackers to execute arbitrary commands as root on openSUSE 13.2.
3
What is the severity of CVE-2014-5220?
CVE-2014-5220 has a severity rating of 7.8 (high).
4
How can I fix CVE-2014-5220?
To fix CVE-2014-5220, upgrade to version 3.3.1-5.14.1 or later of the mdadm package for openSUSE 13.2.
5
Where can I find more information about CVE-2014-5220?
More information about CVE-2014-5220 can be found at the following references: [link1], [link2].