CVE-2011-2649

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
23/08/2011
Last modified:
11/04/2025

Description

Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:marcus_schafer:kiwi:*:*:*:*:*:*:*:* 3.74.1 (including)
cpe:2.3:a:novell:suse_studio_onsite:1.1:*:*:*:*:*:*:*