The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local users to execute arbitrary commands with root privileges via shell metacharacters in the xmlPath argument.
References
Link | Resource |
---|---|
https://bierbaumer.net/security/cve-2014-4677/ | Exploit Third Party Advisory |
https://gpgtools.org/releases/gpgsuite/2015.08/release-notes.html | Release Notes Vendor Advisory |
https://bierbaumer.net/security/cve-2014-4677/ | Exploit Third Party Advisory |
https://gpgtools.org/releases/gpgsuite/2015.08/release-notes.html | Release Notes Vendor Advisory |
Configurations
History
No history.
Information
Published : 2017-02-22 16:59
Updated : 2025-04-20 01:37
NVD link : CVE-2014-4677
Mitre link : CVE-2014-4677
CVE.ORG link : CVE-2014-4677
JSON object : View
Products Affected
gpgtools
- libmacgpg
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')