CVE-2013-4478
Published Dec 7, 2013
Last updated 11 years ago
Overview
- Description
- Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an email attachment.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-94
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:supmua:sup:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CEF11CEF-BE1B-468D-9072-EAEDCCEE7877", "versionEndIncluding": "0.13.2" }, { "criteria": "cpe:2.3:a:supmua:sup:0.13.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35DC51E3-079D-42FD-A055-3E96626015FF" }, { "criteria": "cpe:2.3:a:supmua:sup:0.13.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00BA053E-289D-4360-97E4-F05F03B611E5" }, { "criteria": "cpe:2.3:a:supmua:sup:0.14.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E5DE677F-6E4C-4A72-B5F7-A081DFFF12A4" }, { "criteria": "cpe:2.3:a:supmua:sup:0.14.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "610B9FD9-2C1A-4DFC-A687-FA82BEA28723" } ], "operator": "OR" } ] } ]