CVE-2014-2528

KDirStat <2.7.3 - Command Injection

Title source: llm
STIX 2.1

Description

kcleanup.cpp in KDirStat 2.7.3 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a ' (single quote) character in the directory name, a different vulnerability than CVE-2014-2527.

Scores

EPSS 0.0092
EPSS Percentile 76.2%

Details

Status published
Products (2)
kdirstat_project/kdirstat 2.7.3
opensuse/opensuse 13.1
Published Aug 26, 2014
Tracked Since Feb 18, 2026