#VU44794 Input validation error in SUSE Studio Onsite - CVE-2011-2649
Published: August 24, 2011 / Updated: August 11, 2020
Vulnerability identifier: #VU44794
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2011-2649
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
SUSE Studio Onsite
SUSE Studio Onsite
Software vendor:
Novell
Novell
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.
Remediation
Install update from vendor's website.