[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-7817Date: (C)2014-12-08   (M)2024-02-22


The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.6
Exploit Score: 3.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-62100
SECUNIA-62146
BID-71216
DSA-3142
GLSA-201602-02
RHSA-2014:2023
USN-2432-1
https://sourceware.org/ml/libc-alpha/2014-11/msg00519.html
http://seclists.org/oss-sec/2014/q4/730
gnu-glibc-cve20147817-command-exec(98852)
http://linux.oracle.com/errata/ELSA-2015-0016.html
http://linux.oracle.com/errata/ELSA-2015-0092.html
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
https://sourceware.org/bugzilla/show_bug.cgi?id=17625
https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commitdiff%3Bh=a39208bd7fb76c1b01c127b4c61f9bfd915bfe7c
openSUSE-SU-2015:0351

CWE    1
CWE-20
OVAL    13
oval:org.secpod.oval:def:108466
oval:org.secpod.oval:def:108468
oval:org.secpod.oval:def:1500828
oval:org.secpod.oval:def:501481
...

© SecPod Technologies