Shell Command Injection Vulnerability in kiwi by SUSE
CVE-2011-4195
Currently unrated
Key Information:
- Vendor
Suse
- Vendor
- CVE Published:
- 16 April 2014
What is CVE-2011-4195?
The vulnerability in kiwi allows attackers to execute arbitrary commands by injecting shell metacharacters within an image name. This weakness can lead to unauthorized command execution, potentially compromising the integrity of the system. It affects versions of kiwi prior to 4.98.05, as well as earlier versions of SUSE Studio Onsite and SUSE Studio Extension for System z. Users are encouraged to apply necessary updates to mitigate the risks associated with this vulnerability.