CVE-2014-1928
published 2014-10-25CVE-2014-1928: The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via…
PriorityP425medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.60%
45.0th percentile
The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulnerability than CVE-2014-1927. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-gnupg | < python-gnupg 0.3.6-1 (bookworm) | python-gnupg 0.3.6-1 (bookworm) |
| python-gnupg_project | python-gnupg | <= 0.3.5 | — |
| python-gnupg_project | python-gnupg | — | — |
| python-gnupg_project | python-gnupg | >= 0 < 0.3.6-1 | 0.3.6-1 |
| python-gnupg_project | python-gnupg | >= 0 < 0.3.6-1 | 0.3.6-1 |
| python-gnupg_project | python-gnupg | >= 0 < 0.3.6-1 | 0.3.6-1 |
| python-gnupg_project | python-gnupg | >= 0 < 0.3.6-1 | 0.3.6-1 |
| python-gnupg_project | python-gnupg | >= 0.3.5 < 0.3.6 | 0.3.6 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python-gnupg's shell_quote function does not properly quote strings
osv·2018-11-06·CVSS 7.5
CVE-2014-1927 [HIGH] python-gnupg's shell_quote function does not properly quote strings
python-gnupg's shell_quote function does not properly quote strings
The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
GHSA
python-gnupg's shell_quote function does not properly quote strings
ghsa·2018-11-06·CVSS 7.5
CVE-2014-1927 [HIGH] CWE-20 python-gnupg's shell_quote function does not properly quote strings
python-gnupg's shell_quote function does not properly quote strings
The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
OSV
python-gnupg's shell_quote function does not properly escape characters
osv·2018-11-06·CVSS 7.5
CVE-2014-1928 [HIGH] python-gnupg's shell_quote function does not properly escape characters
python-gnupg's shell_quote function does not properly escape characters
The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulnerability than CVE-2014-1927. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
GHSA
python-gnupg's shell_quote function does not properly escape characters
ghsa·2018-11-06·CVSS 7.5
CVE-2014-1928 [HIGH] CWE-20 python-gnupg's shell_quote function does not properly escape characters
python-gnupg's shell_quote function does not properly escape characters
The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulnerability than CVE-2014-1927. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
OSV
CVE-2014-1927: The shell_quote function in python-gnupg 0
osv·2014-10-25·CVSS 7.5
CVE-2014-1927 [HIGH] CVE-2014-1927: The shell_quote function in python-gnupg 0
The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
OSV
CVE-2014-1928: The shell_quote function in python-gnupg 0
osv·2014-10-25·CVSS 7.5
CVE-2014-1928 [HIGH] CVE-2014-1928: The shell_quote function in python-gnupg 0
The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulnerability than CVE-2014-1927. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
Debian
CVE-2014-1927: python-gnupg - The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, ...
vendor_debian·2014·CVSS 7.5
CVE-2014-1927 [HIGH] CVE-2014-1927: python-gnupg - The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, ...
The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
Scope: local
bookworm: resolved (fixed in 0.3.6-1)
bullseye: resolved (fixed in 0.3.6-1)
forky: resolved (fixed in 0.3.6-1)
sid: resolved (fixed in 0.3.6-1)
trixie: resolved (fixed in 0.3.6-1)
Debian
CVE-2014-1928: python-gnupg - The shell_quote function in python-gnupg 0.3.5 does not properly escape characte...
vendor_debian·2014·CVSS 7.5
CVE-2014-1928 [HIGH] CVE-2014-1928: python-gnupg - The shell_quote function in python-gnupg 0.3.5 does not properly escape characte...
The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulnerability than CVE-2014-1927. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
Scope: local
bookworm: resolved (fixed in 0.3.6-1)
bullseye: resolved (fixed in 0.3.6-1)
forky: resolved (fixed in 0.3.6-1)
sid: resolved (fixed in 0.3.6-1)
trixie: resolved (fixed in 0.3.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-7323 CVE-2014-1927 CVE-2014-1928 CVE-2014-1929 python-gnupg: incorrect fix against shell injection
bugzilla·2014-02-05·CVSS 7.5
CVE-2013-7323 [HIGH] CVE-2013-7323 CVE-2014-1927 CVE-2014-1928 CVE-2014-1929 python-gnupg: incorrect fix against shell injection
CVE-2013-7323 CVE-2014-1927 CVE-2014-1928 CVE-2014-1929 python-gnupg: incorrect fix against shell injection
It was found [1] that the fix for improved shell quoting to guard against shell injection, released in version 0.3.5 [2] of python-gnupg, is not sufficient.
This issue has been reported upstream [3].
[1] http://seclists.org/oss-sec/2014/q1/243
[2] https://code.google.com/p/python-gnupg/
[3] https://code.google.com/p/python-gnupg/issues/detail?id=98#c4
Discussion:
Created python-gnupg tracking bugs for this issue:
Affects: fedora-all [bug 1061600]
---
updates pushed to updates-testing for f19,f20,el6 (and built in rawhide)
---
This was assigned multiple CVE numbers:
CVE-2013-7323 Unrestricted use of unquoted strings in a shell,
within version 0.3.4
CVE-2014-1927 Erroneous
Bugzilla
CVE-2013-0401 OpenJDK: sun.awt.datatransfer.ClassLoaderObjectInputStream class may incorrectly invoke the system class loader (CanSecWest 2013, AWT, 8009305)
bugzilla·2013-03-11·CVSS 10.0
CVE-2013-0401 [CRITICAL] CVE-2013-0401 OpenJDK: sun.awt.datatransfer.ClassLoaderObjectInputStream class may incorrectly invoke the system class loader (CanSecWest 2013, AWT, 8009305)
CVE-2013-0401 OpenJDK: sun.awt.datatransfer.ClassLoaderObjectInputStream class may incorrectly invoke the system class loader (CanSecWest 2013, AWT, 8009305)
The sun.awt.datatransfer.ClassLoaderObjectInputStream class may incorrectly
invoke the system class loader. An untrusted Java application or applet
could possibly use this flaw to bypass certain Java sandbox restrictions.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0401
[2] http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157
[3] http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/
[4] https://twitter.com/thezdi/status/309784608508100608
Discussion:
Public now via Oracle Java SE CPU April 2014:
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928
http://seclists.org/oss-sec/2014/q1/246http://seclists.org/oss-sec/2014/q1/294http://secunia.com/advisories/56616http://secunia.com/advisories/59031http://www.debian.org/security/2014/dsa-2946https://code.google.com/p/python-gnupg/https://code.google.com/p/python-gnupg/issues/detail?id=98http://seclists.org/oss-sec/2014/q1/246http://seclists.org/oss-sec/2014/q1/294http://secunia.com/advisories/56616http://secunia.com/advisories/59031http://www.debian.org/security/2014/dsa-2946https://code.google.com/p/python-gnupg/https://code.google.com/p/python-gnupg/issues/detail?id=98
2014-10-25
Published