PatchSiren cyber security CVE debrief
CVE-2014-4677 Gpgtools CVE debrief
CVE-2014-4677 describes a high-severity local privilege escalation in the installerHelper subcomponent of Libmacgpg used by GPG Suite. The vulnerable installPackage function can let a local user inject shell metacharacters through the xmlPath argument and execute arbitrary commands with root privileges. NVD rates the issue 7.8 (HIGH) and maps it to CWE-77.
- Vendor
- Gpgtools
- Product
- Libmacgpg
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-22
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-22
- Advisory updated
- 2026-05-13
Who should care
Administrators and users running affected GPG Suite / Libmacgpg versions, especially on systems where local users may have interactive access or other ways to submit untrusted local input.
Technical summary
The issue is in installPackage within installerHelper in Libmacgpg. According to the supplied NVD description, unsafely handling the xmlPath argument allows shell metacharacter injection, resulting in arbitrary command execution as root. NVD lists affected Libmacgpg versions up to 0.6, and the vulnerability is categorized as CWE-77 (Command Injection).
Defensive priority
High. This is a local attack that can become root-level code execution, so exposure on shared or user-accessible systems should be treated as urgent.
Recommended defensive actions
- Upgrade GPG Suite / Libmacgpg from any version before 2015.06 to a patched release referenced by the vendor advisory.
- Confirm whether any installed Libmacgpg instances match the affected version range listed by NVD (up to 0.6).
- Review systems where untrusted local users can run processes or influence package installation workflows.
- Monitor the vendor release notes and official CVE/NVD entries for remediation details and version guidance.
Evidence notes
The supplied NVD record states that the installPackage function in installerHelper allows local users to execute arbitrary commands with root privileges via shell metacharacters in the xmlPath argument. It also lists the vulnerability class as CWE-77 and includes an affected CPE range for gpgtools:libmacgpg up to version 0.6. Vendor release notes and a third-party advisory are included in the supplied references.
Sources and references
Verified primary and authoritative sources
-
CVE-2014-4677 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2014-4677
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2014-4677 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2014-4677
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://bierbaumer.net/security/cve-2014-4677/
[email protected] - Exploit, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://gpgtools.org/releases/gpgsuite/2015.08/release-notes.html
[email protected] - Release Notes, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.