vendor:
Gnome Partition Editor
by:
W. Ettlinger
5.5
CVSS
MEDIUM
OS Command Execution
78
CWE
Product Name: Gnome Partition Editor
Affected Version From: <=0.14.1
Affected Version To: >=0.15.0
Patch Exists: YES
Related CWE: CVE-2014-7208
CPE: a:gparted:gnome_partition_editor:0.14.1
Platforms Tested:
2014
OS Command Execution
GParted <=0.14.1 does not properly sanitize strings before passing them as parameters to an OS command. Those commands are executed using root privileges.
Mitigation:
Upgrade to GParted version >=0.15.0 or apply the fix for CVE-2014-7208 to version <=0.14.1