PatchSiren

PatchSiren cyber security CVE debrief

CVE-2014-4677 Gpgtools CVE debrief

CVE-2014-4677 describes a high-severity local privilege escalation in the installerHelper subcomponent of Libmacgpg used by GPG Suite. The vulnerable installPackage function can let a local user inject shell metacharacters through the xmlPath argument and execute arbitrary commands with root privileges. NVD rates the issue 7.8 (HIGH) and maps it to CWE-77.

Vendor
Gpgtools
Product
Libmacgpg
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-22
Original CVE updated
2026-05-13
Advisory published
2017-02-22
Advisory updated
2026-05-13

Who should care

Administrators and users running affected GPG Suite / Libmacgpg versions, especially on systems where local users may have interactive access or other ways to submit untrusted local input.

Technical summary

The issue is in installPackage within installerHelper in Libmacgpg. According to the supplied NVD description, unsafely handling the xmlPath argument allows shell metacharacter injection, resulting in arbitrary command execution as root. NVD lists affected Libmacgpg versions up to 0.6, and the vulnerability is categorized as CWE-77 (Command Injection).

Defensive priority

High. This is a local attack that can become root-level code execution, so exposure on shared or user-accessible systems should be treated as urgent.

Recommended defensive actions

  • Upgrade GPG Suite / Libmacgpg from any version before 2015.06 to a patched release referenced by the vendor advisory.
  • Confirm whether any installed Libmacgpg instances match the affected version range listed by NVD (up to 0.6).
  • Review systems where untrusted local users can run processes or influence package installation workflows.
  • Monitor the vendor release notes and official CVE/NVD entries for remediation details and version guidance.

Evidence notes

The supplied NVD record states that the installPackage function in installerHelper allows local users to execute arbitrary commands with root privileges via shell metacharacters in the xmlPath argument. It also lists the vulnerability class as CWE-77 and includes an affected CPE range for gpgtools:libmacgpg up to version 0.6. Vendor release notes and a third-party advisory are included in the supplied references.

Sources and references

Verified primary and authoritative sources

  • CVE-2014-4677 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2014-4677

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2014-4677 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2014-4677

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.