kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a " (double quote) character in the directory name, a different vulnerability than CVE-2014-2528. <a href"http://cwe.mitre.org/data/definitions/77.html" target"_blank">CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')</a>
Publication date: Tue, 26 Aug 2014 19:55:00 +0000