Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2014-7817

MEDIUM · 4.6 CVSS Gepubliceerd: CWE-20

Beschrijving

The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".

Vendors

Canonical Debian Gnu Opensuse

Affected products

Ubuntu Linux Debian Linux Glibc Opensuse

References