[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-1929Date: (C)2014-10-28   (M)2023-12-22


python-gnupg 0.3.5 and 0.3.6 allows context-dependent attackers to have an unspecified impact via vectors related to "option injection through positional arguments." NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.4
Exploit Score: 3.4
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-59031
DSA-2946
http://seclists.org/oss-sec/2014/q1/245
http://seclists.org/oss-sec/2014/q1/335

CPE    2
cpe:/a:python-gnupg_project:python-gnupg:0.3.5
cpe:/a:python-gnupg_project:python-gnupg:0.3.6
CWE    1
CWE-20
OVAL    2
oval:org.secpod.oval:def:106429
oval:org.secpod.oval:def:106427

© SecPod Technologies