CVE-2014-5220

The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
Configurations

Configuration 1 (hide)

cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:mdadm_project:mdadm:*:*:*:*:*:*:*:*

History

07 Nov 2023, 02:20

Type Values Removed Values Added
References (CONFIRM) https://bugzilla.suse.com/show_bug.cgi?id=910500 - Issue Tracking, Vendor Advisory () https://bugzilla.suse.com/show_bug.cgi?id=910500 -
References (SUSE) https://lists.opensuse.org/opensuse-updates/2015-02/msg00069.html - Mailing List, Vendor Advisory () https://lists.opensuse.org/opensuse-updates/2015-02/msg00069.html -

Information

Published : 2018-06-08 17:29

Updated : 2024-02-28 16:25


NVD link : CVE-2014-5220

Mitre link : CVE-2014-5220

CVE.ORG link : CVE-2014-5220


JSON object : View

Products Affected

opensuse

  • opensuse

mdadm_project

  • mdadm
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')