CVE-2014-1927
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
La función shell_quote en python-gnupg 0.3.5 no cita debidamente cadenas, lo que permite a atacantes dependientes de contexto ejecutar código arbitrario a través de metacaracteres de shell en vectores no especificados, tal y como fue demostrado mediante el uso de secuencias de sustitución de comandos '$(', una vulnerabilidad diferente a CVE-2014-1928. NOTA: esta vulnerabilidad existe debido a una solución incompleta para CVE-2013-7323.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-02-09 CVE Reserved
- 2014-06-05 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2024-10-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/56616 | Third Party Advisory | |
http://secunia.com/advisories/59031 | Third Party Advisory | |
https://code.google.com/p/python-gnupg | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
http://seclists.org/oss-sec/2014/q1/245 | 2024-08-06 | |
http://seclists.org/oss-sec/2014/q1/294 | 2024-08-06 | |
https://code.google.com/p/python-gnupg/issues/detail?id=98 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2014/dsa-2946 | 2014-10-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Python-gnupg Project Search vendor "Python-gnupg Project" | Python-gnupg Search vendor "Python-gnupg Project" for product "Python-gnupg" | 0.3.5 Search vendor "Python-gnupg Project" for product "Python-gnupg" and version "0.3.5" | - |
Affected
|