CVE-2016-7787: Code Injection
Published Dec 23, 2016
·Updated
A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.
Affected Software
3 affected components
KDE Kde-cli-tools
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Remediation
Patch Available
Event History
Dec 23, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7787?
CVE-2016-7787 is rated as a medium severity vulnerability.
2
How do I fix CVE-2016-7787?
To fix CVE-2016-7787, update the KDE CLI Tools package to the latest version available for your operating system.
3
What does CVE-2016-7787 affect?
CVE-2016-7787 specifically affects KDE CLI Tools used in openSUSE Leap 42.1 and openSUSE 13.2.
4
How does CVE-2016-7787 impact users?
CVE-2016-7787 can lead to users being unaware of the full set of commands they are executing as a super user, potentially increasing security risks.
5
Is there a workaround for CVE-2016-7787?
There is no specific workaround for CVE-2016-7787 other than applying the relevant updates.