CVE-2011-4349

colord < 0.1.15 - SQL Injection via Device ID, Property, or Profile ID

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in (1) cd-mapping-db.c and (2) cd-device-db.c in colord before 0.1.15 allow local users to execute arbitrary SQL commands via vectors related to color devices and (a) device id, (b) property, or (c) profile id.

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50814
Various Sources vendor-advisory x_refsource_ubuntu
http://ubuntu.com/usn/usn-1289-1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46940
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/11/25/4
Issue Tracking x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=757171
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47160
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-December/070518.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-December/070450.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/11/25/3

Scores

EPSS 0.0046
EPSS Percentile 37.2%

Details

CWE
CWE-89
Status published
Products (15)
freedesktop/colord 0.1.0
freedesktop/colord 0.1.1
freedesktop/colord 0.1.2
freedesktop/colord 0.1.3
freedesktop/colord 0.1.4
freedesktop/colord 0.1.5
freedesktop/colord 0.1.6
freedesktop/colord 0.1.7
freedesktop/colord 0.1.8
freedesktop/colord 0.1.9
... and 5 more
Published Dec 10, 2011
Tracked Since Feb 18, 2026