Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8119

Опубликовано: 29 дек. 2017
Источник: debian
EPSS Низкий

Описание

The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
netcfnot-affectedpackage

Примечания

  • Issue is in the way the netcf's find_ifcfg_path() function processed

  • certain XPath expressions according to Red Hat bugzilla.

  • The fix consists in augeas getting a new API aug_escape_name which

  • netcf needs to use.

  • https://bugzilla.redhat.com/show_bug.cgi?id=1172176#c3

  • https://www.redhat.com/archives/augeas-devel/2014-December/msg00000.html

  • The affected code is only in drv_redhat.c and drv_suse.c and the Debian

  • build not affected.

EPSS

Процентиль: 84%
0.02408
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.

redhat
больше 10 лет назад

The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.

CVSS3: 7.5
nvd
больше 7 лет назад

The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.

suse-cvrf
почти 10 лет назад

Security update for augeas

suse-cvrf
около 10 лет назад

Security update for augeas

EPSS

Процентиль: 84%
0.02408
Низкий