CVE-2011-4349
https://notcve.org/view.php?id=CVE-2011-4349
Multiple SQL injection vulnerabilities in (1) cd-mapping-db.c and (2) cd-device-db.c in colord before 0.1.15 allow local users to execute arbitrary SQL commands via vectors related to color devices and (a) device id, (b) property, or (c) profile id. Múltiples vulnerabilidades de inyección SQL en (1) cd-mapping-db.c y (2) CD-dispositivo-db.c en colord antes de v0.1.15 permite a usuarios locales ejecutar comandos SQL a través de vectores relacionados con los dispositivos de color y (a) el Identificador del dispositivo, (b) la propiedad o (c) el Identificador del perfil. • http://gitorious.org/colord/master/commit/1fadd90afcb4bbc47513466ee9bb1e4a8632ac3b http://gitorious.org/colord/master/commit/36549e0ed255e7dfa7852d08a75dd5f00cbd270e http://lists.fedoraproject.org/pipermail/package-announce/2011-December/070450.html http://lists.fedoraproject.org/pipermail/package-announce/2011-December/070518.html http://secunia.com/advisories/46940 http://secunia.com/advisories/47160 http://ubuntu.com/usn/usn-1289-1 http://www.openwall.com/lists/oss-security/2011/11/25/3 http://www.openwall. • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •