CVE-2014-2527

KDirStat 2.7.0 - Command Injection

Title source: llm
STIX 2.1

Description

kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a " (double quote) character in the directory name, a different vulnerability than CVE-2014-2528.

Scores

EPSS 0.0095
EPSS Percentile 76.5%

Details

Status published
Products (2)
kdirstat_project/kdirstat 2.7.0
opensuse/opensuse 13.1
Published Aug 26, 2014
Tracked Since Feb 18, 2026