{ "id": "CVE-2011-4349", "sourceIdentifier": "secalert@redhat.com", "published": "2011-12-10T17:55:01.600", "lastModified": "2011-12-12T05:00:00.000", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Multiple SQL injection vulnerabilities in (1) cd-mapping-db.c and (2) cd-device-db.c in colord before 0.1.15 allow local users to execute arbitrary SQL commands via vectors related to color devices and (a) device id, (b) property, or (c) profile id." }, { "lang": "es", "value": "M\u00faltiples vulnerabilidades de inyecci\u00f3n SQL en (1) cd-mapping-db.c y (2) CD-dispositivo-db.c en colord antes de v0.1.15 permite a usuarios locales ejecutar comandos SQL a trav\u00e9s de vectores relacionados con los dispositivos de color y (a) el Identificador del dispositivo, (b) la propiedad o (c) el Identificador del perfil." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 4.6 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 3.9, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-89" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:*:*:*:*:*:*:*:*", "versionEndIncluding": "0.1.14", "matchCriteriaId": "CD9D7F67-B0B9-4718-A4AD-43E11CB911D6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.0:*:*:*:*:*:*:*", "matchCriteriaId": "76935BB4-6F70-4330-8095-1C678E5008B2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "B0151925-B3FD-4F66-873D-5D02D4EE5279" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "929CE81F-9E67-4AC0-8F2D-0B42173A86D7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "71A33D61-1580-4482-BFB2-F85DC9FA3EDD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.4:*:*:*:*:*:*:*", "matchCriteriaId": "53AF414A-06D5-4C18-80E9-728BDBB89BF5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.5:*:*:*:*:*:*:*", "matchCriteriaId": "F2C0CA8E-D04C-4A65-9398-820D10367F6D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.6:*:*:*:*:*:*:*", "matchCriteriaId": "9AC9D44E-7100-489A-BC2A-FFCFF0981B19" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.7:*:*:*:*:*:*:*", "matchCriteriaId": "212E062D-8254-4925-9BEA-316B0AB45F79" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.8:*:*:*:*:*:*:*", "matchCriteriaId": "1ED10031-E979-4F25-B8B4-7AD251CBFAD9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.9:*:*:*:*:*:*:*", "matchCriteriaId": "93945AC7-C34D-43BC-9371-68039D851DDE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.10:*:*:*:*:*:*:*", "matchCriteriaId": "B971026A-0D3B-4125-A6F1-A8E0C81493F1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.11:*:*:*:*:*:*:*", "matchCriteriaId": "D496542A-7EC5-4D56-AAA8-D781470EFFFD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.12:*:*:*:*:*:*:*", "matchCriteriaId": "4028A7D6-82F5-4F46-84CF-BEC034675EDA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:freedesktop:colord:0.1.13:*:*:*:*:*:*:*", "matchCriteriaId": "4D3CE7CE-CBF5-45B0-BCB2-D6C88588FAA1" } ] } ] } ], "references": [ { "url": "http://gitorious.org/colord/master/commit/1fadd90afcb4bbc47513466ee9bb1e4a8632ac3b", "source": "secalert@redhat.com" }, { "url": "http://gitorious.org/colord/master/commit/36549e0ed255e7dfa7852d08a75dd5f00cbd270e", "source": "secalert@redhat.com" }, { "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-December/070450.html", "source": "secalert@redhat.com" }, { "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-December/070518.html", "source": "secalert@redhat.com" }, { "url": "http://www.openwall.com/lists/oss-security/2011/11/25/3", "source": "secalert@redhat.com" }, { "url": "http://www.openwall.com/lists/oss-security/2011/11/25/4", "source": "secalert@redhat.com" }, { "url": "http://www.securityfocus.com/bid/50814", "source": "secalert@redhat.com" }, { "url": "https://bugs.freedesktop.org/show_bug.cgi?id=42904", "source": "secalert@redhat.com", "tags": [ "Patch" ] }, { "url": "https://bugzilla.redhat.com/show_bug.cgi?id=757171", "source": "secalert@redhat.com" } ] }