CVE-2014-2886: Nongnu Gksu
Medium severity, CVSS 6.8. EPSS: 2.2% chance of exploitation in the next 30 days.
GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situations involving an untrusted substring within this argument, as demonstrated by an untrusted filename encountered during installation of a VirtualBox extension pack.
Affected products
- Nongnu Gksu: version 2.0.2 only
Published 2014-09-18. Last modified 2026-06-17.