CVE-2014-0475

Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 29 Jul 2014, 14:00
Last modified:06 Aug 2024, 09:20

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.8 MEDIUM
v2.0 (nvd)
EPSS Score
0.78% LOW
1% probability +0.51%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Jul 2014, 14:00
Published
Vulnerability first disclosed
06 Aug 2024, 09:20
Last Modified
Vulnerability information updated

Description

Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.

CVSS Metrics

  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.78% Percentile: 74%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • gnuglibc

    ≤ 2.19 | 2.0 | 2.0.1 | 2.0.2 | 2.0.3 | 2.0.4 | 2.0.5 | 2.0.6 | 2.1 | 2.11 | 2.1.1.6 | 2.12 | 2.13 | 2.19 | 2.10.1 | 2.11.1 | 2.11.2 | 2.11.3 | 2.12.1 | 2.12.2 | 2.14 | 2.14.1 | 2.15 | 2.16 | 2.17 | 2.18

References (10)