The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
References
Configurations
History
No history.
Information
Published : 2018-06-08 17:29
Updated : 2024-02-04 19:46
NVD link : CVE-2014-5220
Mitre link : CVE-2014-5220
CVE.ORG link : CVE-2014-5220
JSON object : View
Products Affected
mdadm_project
- mdadm
opensuse
- opensuse
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')