CVE-2014-7209

run-mailcap <3.52-1+deb7u1 - Command Injection

Title source: llm
STIX 2.1

Description

run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71797
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61892
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99570
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62079
Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2014/dsa-3114
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/12/31/8

Scores

EPSS 0.0270
EPSS Percentile 84.0%

Details

CWE
CWE-77
Status published
Products (1)
debian/mime-support < 3.52-1
Published Jan 06, 2015
Tracked Since Feb 18, 2026