CVE-2013-4376

The setgid wrapper libx2go-server-db-sqlite3-wrapper.c in X2Go Server before 4.0.0.2 allows remote attackers to execute arbitrary code via unspecified vectors, related to the path to libx2go-server-db-sqlite3-wrapper.pl.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:x2go:x2go_server:*:*:*:*:*:*:*:*
cpe:2.3:a:x2go:x2go_server:4.0.0.0:*:*:*:*:*:*:*

History

07 Nov 2023, 02:16

Type Values Removed Values Added
References
  • {'url': 'http://code.x2go.org/gitweb?p=x2goserver.git;a=commit;h=42264c88d7885474ebe3763b2991681ddfcfa69a', 'name': 'http://code.x2go.org/gitweb?p=x2goserver.git;a=commit;h=42264c88d7885474ebe3763b2991681ddfcfa69a', 'tags': ['Patch'], 'refsource': 'CONFIRM'}
  • () http://code.x2go.org/gitweb?p=x2goserver.git%3Ba=commit%3Bh=42264c88d7885474ebe3763b2991681ddfcfa69a -

Information

Published : 2013-12-09 16:36

Updated : 2024-02-28 12:00


NVD link : CVE-2013-4376

Mitre link : CVE-2013-4376

CVE.ORG link : CVE-2013-4376


JSON object : View

Products Affected

x2go

  • x2go_server
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')