Unrated severityNVD Advisory· Published Dec 10, 2011· Updated Apr 29, 2026
CVE-2011-4349
CVE-2011-4349
Description
Multiple SQL injection vulnerabilities in (1) cd-mapping-db.c and (2) cd-device-db.c in colord before 0.1.15 allow local users to execute arbitrary SQL commands via vectors related to color devices and (a) device id, (b) property, or (c) profile id.
Affected products
15cpe:2.3:a:freedesktop:colord:*:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:freedesktop:colord:*:*:*:*:*:*:*:*range: <=0.1.14
- cpe:2.3:a:freedesktop:colord:0.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.11:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.12:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.13:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:freedesktop:colord:0.1.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- bugs.freedesktop.org/show_bug.cginvdPatch
- secunia.com/advisories/46940nvdVendor Advisory
- secunia.com/advisories/47160nvdVendor Advisory
- gitorious.org/colord/master/commit/1fadd90afcb4bbc47513466ee9bb1e4a8632ac3bnvd
- gitorious.org/colord/master/commit/36549e0ed255e7dfa7852d08a75dd5f00cbd270envd
- lists.fedoraproject.org/pipermail/package-announce/2011-December/070450.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-December/070518.htmlnvd
- ubuntu.com/usn/usn-1289-1nvd
- www.openwall.com/lists/oss-security/2011/11/25/3nvd
- www.openwall.com/lists/oss-security/2011/11/25/4nvd
- www.securityfocus.com/bid/50814nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.