CVE-2011-1842 describes a critical vulnerability in the D-Bus backend of language-selector versions prior to 0.6.7, specifically affecting Ubuntu systems. This flaw allows local users to escalate privileges by injecting shell metacharacters into string arguments for the SetSystemDefaultLangEnv and SetSystemDefaultLanguageEnv functions due to insufficient input validation. With a CVSS score of 7.2, this vulnerability presents a high risk, enabling complete compromise of confidentiality, integrity, and availability from a local attack. While no active exploitation, public exploit code, or significant community discussion has been observed, the potential for privilege escalation makes it a serious concern for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.6.6CPE matchmatch criteria | cpe:2.3:a:ubuntu:language-selector:*:*:*:*:*:*:*:* | ||
0.0\+baz20050531CPE matchmatch criteria | cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050531:*:*:*:*:*:*:* | ||
0.0\+baz20050609CPE matchmatch criteria | cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050609:*:*:*:*:*:*:* | ||
0.0\+baz20050614CPE matchmatch criteria | cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050614:*:*:*:*:*:*:* | ||
0.0\+baz20050808CPE matchmatch criteria | cpe:2.3:a:ubuntu:language-selector:0.0\+baz20050808:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.