Sploitus

CVE-2014-2886

No indexed exploits for CVE-2014-2886 yet

GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situations involving an untrusted substring within this argument, as demonstrated by an untrusted filename encountered during installation of a VirtualBox extension pack.

Affected products
Gksu, Virtualbox
Nongnu Gksu
= 2.0.2
Fix
Available
CVSS 2.0
6.8 MEDIUM
EPSS
2.2% (81th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2014-09-18
CVE-2014-2886 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2014-2886 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2014-2886 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.