command injection in ckbcomp
Bug #782705 reported by
Emanuel Bronshtein
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
console-setup (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: console-setup
/usr/bin/ckbcomp have command injection bug .
test case :
root@emanuel-
root@emanuel-
WARNING: Can not find "" in "/tmp/CKB".
keymaps 0-127
strings as usual
cat: /etc/console-
Systeminj
the bug can be found at :
if ($charmap && -f "/etc/console-
system("cat /etc/console-
}
Related branches
Changed in console-setup (Ubuntu): | |
status: | New → Fix Committed |
To post a comment you must log in.
fix : setup/compose. ${charmap} .inc");
system("cat" , "/etc/console-