VulnerabilityModified
CVE-2006-1865
Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary commands via crafted filenames that inject command line arguments when Beagle launches external helper applications while indexing.
HIGH 7.5EPSS 3.48%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.48%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary commands via crafted filenames that inject command line arguments when Beagle launches external helper applications while indexing.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.48% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-88
- Affected
- beagle project/beagle
- Source
- cve@mitre.org
References
- http://lists.seifried.org/pipermail/security/2006-April/013163.htmlBroken Link
- http://scary.beasts.org/security/CESA-2006-002.htmlThird Party Advisory
- http://secunia.com/advisories/19778Broken Link, Vendor Advisory
- http://secunia.com/advisories/19781Broken Link, Vendor Advisory
- http://secunia.com/advisories/19897Broken Link, Vendor Advisory
- http://www.novell.com/linux/security/advisories/2006_04_28.htmlBroken Link
- http://www.osvdb.org/24938Broken Link
- http://www.securityfocus.com/bid/17611Broken Link, Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189282Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26104Third Party Advisory, VDB Entry
- http://lists.seifried.org/pipermail/security/2006-April/013163.htmlBroken Link
- http://scary.beasts.org/security/CESA-2006-002.htmlThird Party Advisory
- http://secunia.com/advisories/19778Broken Link, Vendor Advisory
- http://secunia.com/advisories/19781Broken Link, Vendor Advisory
- http://secunia.com/advisories/19897Broken Link, Vendor Advisory
- http://www.novell.com/linux/security/advisories/2006_04_28.htmlBroken Link
- http://www.osvdb.org/24938Broken Link
- http://www.securityfocus.com/bid/17611Broken Link, Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189282Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26104Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.