Vulnerability Name:

CVE-2014-2528 (CCN-92039)

Assigned:2014-03-17
Published:2014-03-17
Updated:2018-10-30
Summary:kcleanup.cpp in KDirStat 2.7.3 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a ' (single quote) character in the directory name, a different vulnerability than CVE-2014-2527.

CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2014-2528

Source: CCN
Type: KDirStat Web site
KDirStat

Source: SUSE
Type: Vendor Advisory
openSUSE-SU-2014:0984

Source: CCN
Type: oss-security Mailing List, Mon 17 Mar 2014
CVE request: kdirstat, insufficient quote escaping leading to arbitrary command execution

Source: CCN
Type: SA56908
K4DirStat Directory Names OS Command Injection Vulnerability

Source: MLIST
Type: UNKNOWN
[oss-security] 20140317 CVE request: kdirstat, insufficient quote escaping leading to arbitrary command execution

Source: MLIST
Type: Patch
[oss-security] 20140318 Re: CVE request: kdirstat, insufficient quote escaping leading to arbitrary command execution

Source: CCN
Type: BID-66297
K4DirStat CVE-2014-2527 Remote Command Injection Vulnerability

Source: CONFIRM
Type: Exploit, Patch
https://bitbucket.org/jeromerobert/k4dirstat/commits/1ad2e96d73fa06cd9be0f3749b337c03575016aa#chg-src/kcleanup.cpp

Source: CONFIRM
Type: UNKNOWN
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741659

Source: XF
Type: UNKNOWN
kdirstat-cve20142528-command-exec(92039)

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-2528

Vulnerable Configuration:Configuration 1:
  • cpe:/a:kdirstat_project:kdirstat:2.7.3:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:13.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20142528
    V
    CVE-2014-2528
    2022-06-30
    oval:org.opensuse.security:def:112502
    P
    kdirstat-2.4.4-277.11 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:33108
    P
    Security update for java-1_7_1-ibm (Moderate) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:30160
    P
    Security update for openssh (Important)
    2021-12-06
    oval:org.opensuse.security:def:33059
    P
    Security update for openssh (Important)
    2021-12-06
    oval:org.opensuse.security:def:31715
    P
    Security update for the Linux Kernel (Important)
    2021-12-06
    oval:org.opensuse.security:def:30264
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:105995
    P
    kdirstat-2.4.4-277.11 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:26138
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:55953
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:33954
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:30215
    P
    Security update for xterm (Important)
    2021-06-18
    oval:org.opensuse.security:def:55915
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-15
    oval:org.opensuse.security:def:56034
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:42570
    P
    kdirstat-2.4.4-255.28.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36163
    P
    kdirstat-2.4.4-255.28.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:31630
    P
    Security update for polkit (Important)
    2021-06-03
    oval:org.opensuse.security:def:31629
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:32083
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:33897
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:34415
    P
    Security update for apache-commons-io (Moderate)
    2021-04-26
    oval:org.opensuse.security:def:33891
    P
    Security update for xorg-x11-server (Important)
    2021-04-13
    oval:org.opensuse.security:def:28962
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:34043
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:33087
    P
    Security update for java-1_8_0-ibm (Important)
    2021-02-26
    oval:org.opensuse.security:def:55841
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:32239
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:33002
    P
    Security update for kernel-source (Important)
    2021-02-05
    oval:org.opensuse.security:def:30007
    P
    Security update for ImageMagick (Important)
    2021-01-22
    oval:org.opensuse.security:def:31641
    P
    Security update for ImageMagick (Important)
    2021-01-22
    oval:org.opensuse.security:def:55190
    P
    Security update for flac (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:33665
    P
    Security update for java-1_7_1-ibm (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:26054
    P
    Security update for flac (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:57384
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:27272
    P
    ppp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27557
    P
    rubygem-activesupport-3_2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27902
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:29165
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:28373
    P
    Recommended update for python-setuptools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28584
    P
    Security update for libvirt
    2020-12-01
    oval:org.opensuse.security:def:30322
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29645
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:30303
    P
    Security update for sudo (Important)
    2020-12-01
    oval:org.opensuse.security:def:54533
    P
    libarchive13 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31939
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:32295
    P
    Security update for ppp (Important)
    2020-12-01
    oval:org.opensuse.security:def:33214
    P
    ntp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32383
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32608
    P
    systemtap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34371
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26444
    P
    Security update for mumble (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25788
    P
    Security update for zeromq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26430
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28721
    P
    Security update for kdirstat
    2020-12-01
    oval:org.opensuse.security:def:27283
    P
    quagga on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27614
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:27951
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:29803
    P
    Security update for inn (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28374
    P
    Security update for quagga (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28669
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:29016
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:30366
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29560
    P
    Security update for NetworkManager
    2020-12-01
    oval:org.opensuse.security:def:29777
    P
    Security update for GnuTLS
    2020-12-01
    oval:org.opensuse.security:def:54673
    P
    rsyslog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55356
    P
    pigz on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33126
    P
    kdirstat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31996
    P
    Security update for java-1_7_1-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32344
    P
    Security update for spice (Important)
    2020-12-01
    oval:org.opensuse.security:def:33852
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32384
    P
    Security update for tiff (Low)
    2020-12-01
    oval:org.opensuse.security:def:32702
    P
    libadns1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33570
    P
    Security update for LibVNCServer (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33801
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34200
    P
    Security update for Perl
    2020-12-01
    oval:org.opensuse.security:def:26488
    P
    Security update for cacti, cacti-spine (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25712
    P
    Security update for python36 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25916
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:26289
    P
    Security update for sane-backends (Important)
    2020-12-01
    oval:org.opensuse.security:def:28004
    P
    Security update for Xerces-c (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27347
    P
    libslp1-openssl1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27698
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:27990
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:29839
    P
    Security update for kdirstat
    2020-12-01
    oval:org.opensuse.security:def:28385
    P
    Security update for rubygem-activesupport-3_2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28726
    P
    Security update for krb5
    2020-12-01
    oval:org.opensuse.security:def:29065
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:31004
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29561
    P
    Security update for NetworkManager-gnome
    2020-12-01
    oval:org.opensuse.security:def:29864
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:54510
    P
    libFLAC++6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54911
    P
    libpng16-16 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55641
    P
    Security update for gdk-pixbuf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32405
    P
    Security update for wavpack (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33147
    P
    libexif on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32395
    P
    Security update for unrar (Important)
    2020-12-01
    oval:org.opensuse.security:def:32759
    P
    openvpn on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35053
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:33571
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:34258
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27126
    P
    freeradius-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25713
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25997
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26342
    P
    Security update for openjpeg2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28048
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27271
    P
    ppc64-diag on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27475
    P
    libpulse-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27849
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29121
    P
    Security update for java-1_7_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28453
    P
    Security update for xen (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28810
    P
    Security update for postgresql91
    2020-12-01
    oval:org.opensuse.security:def:29104
    P
    Security update for gstreamer-0_10-plugins-base (Important)
    2020-12-01
    oval:org.opensuse.security:def:31041
    P
    Security update for kdirstat
    2020-12-01
    oval:org.opensuse.security:def:29572
    P
    Security update for amanda (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29921
    P
    Security update for libexif
    2020-12-01
    oval:org.opensuse.security:def:57310
    P
    Security update for compat-wireless, compat-wireless-debuginfo, compat-wireless-debugsource, compat-wireless-kmp-default, compat-wireless-kmp-pae, compat-wireless-kmp-trace, compat-wireless-kmp-xen
    2020-12-01
    oval:org.opensuse.security:def:54511
    P
    libHX28 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55084
    P
    cups-filters on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55749
    P
    Security update for xscreensaver (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32449
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:31847
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33170
    P
    libotr2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32473
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:32846
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34346
    P
    Security update for squid3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:35093
    P
    Security update for kdirstat
    2020-12-01
    oval:org.opensuse.security:def:33582
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:34307
    P
    Security update for quagga (Important)
    2020-12-01
    oval:org.opensuse.security:def:27161
    P
    kdirstat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25724
    P
    Security update for postgresql10 (Low)
    2020-12-01
    oval:org.opensuse.security:def:26391
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:28686
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.mitre.oval:def:26062
    P
    SUSE-SU-2014:0930-1 -- Security update for kdirstat
    2014-09-15
    oval:com.ubuntu.artful:def:20142528000
    V
    CVE-2014-2528 on Ubuntu 17.10 (artful) - medium.
    2014-08-26
    oval:com.ubuntu.disco:def:201425280000000
    V
    CVE-2014-2528 on Ubuntu 19.04 (disco) - medium.
    2014-08-26
    oval:com.ubuntu.trusty:def:20142528000
    V
    CVE-2014-2528 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-08-26
    oval:com.ubuntu.cosmic:def:201425280000000
    V
    CVE-2014-2528 on Ubuntu 18.10 (cosmic) - medium.
    2014-08-26
    oval:com.ubuntu.bionic:def:20142528000
    V
    CVE-2014-2528 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-08-26
    oval:com.ubuntu.xenial:def:20142528000
    V
    CVE-2014-2528 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-08-26
    oval:com.ubuntu.bionic:def:201425280000000
    V
    CVE-2014-2528 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-08-26
    oval:com.ubuntu.cosmic:def:20142528000
    V
    CVE-2014-2528 on Ubuntu 18.10 (cosmic) - medium.
    2014-08-26
    oval:com.ubuntu.xenial:def:201425280000000
    V
    CVE-2014-2528 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-08-26
    oval:com.ubuntu.precise:def:20142528000
    V
    CVE-2014-2528 on Ubuntu 12.04 LTS (precise) - medium.
    2014-08-26
    oval:org.opensuse.security:def:80018
    P
    Security update for kdirstat
    2014-07-06
    BACK
    kdirstat_project kdirstat 2.7.3
    opensuse opensuse 13.1