CVE-2014-9114: Command Injection
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
Other sources
Sebastian Krahmer reported a command injection flaw in blkid. This could possibly result in command execution with root privileges (for example, when running blkid on a malicious USB drive):
http://www.openwall.com/lists/oss-security/2014/11/26/13
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9114?
CVE-2014-9114 has a high severity rating due to the potential for arbitrary code execution with root privileges.
How do I fix CVE-2014-9114?
To fix CVE-2014-9114, update to the latest version of the util-linux package that addresses this vulnerability.
Which versions are affected by CVE-2014-9114?
CVE-2014-9114 affects util-linux versions prior to 2.26rc-1 on specific versions of openSUSE and Fedora.
Can CVE-2014-9114 be exploited by a remote attacker?
CVE-2014-9114 is primarily a local attack vector that can be exploited when users run blkid on a malicious USB drive.
What are the potential consequences of CVE-2014-9114?
The potential consequences of CVE-2014-9114 include unauthorized execution of commands with elevated privileges, which could compromise system security.