CVE-2011-1842

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
03/05/2011
Last modified:
11/04/2025

Description

dbus_backend/lsd.py in the D-Bus backend in language-selector before 0.6.7 does not validate the arguments to the (1) SetSystemDefaultLangEnv and (2) SetSystemDefaultLanguageEnv functions, which allows local users to gain privileges via shell metacharacters in a string argument, a different vulnerability than CVE-2011-0729.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ubuntu:language-selector:*:*:*:*:*:*:*:* 0.6.6 (including)
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050531:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050609:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050614:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050808:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050811:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050819:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050819.2:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050822:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050823:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050824:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050912:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050926:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050927:*:*:*:*:*:*:*
cpe:2.3:a:ubuntu:language-selector:0.1:*:*:*:*:*:*:*