OS command injection in growl - CVE-2017-16042

 

OS command injection in growl - CVE-2017-16042

Published: August 6, 2018 / Updated: August 8, 2018


Vulnerability identifier: #VU14269
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16042
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to insufficient validation of user supplied input. A remote unauthenticated attacker can submit specially crafted data to inject and execute arbitrary shell commands.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

growl
Apache Avro

How to mitigate CVE-2017-16042

Update to version 1.10.2 or later.

growl - addressed in versions 1.10.2, 1.10.3, 1.10.4, 1.10.5
Apache Avro - update to 1.9.2

External References

Related Security Bulletins