Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-1422

Опубликовано: 22 июл. 2020
Источник: nvd
CVSS3: 5
CVSS2: 1.9
EPSS Низкий

Описание

In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the application will honour incorrect, cached permissions. This is because the cache was not ordered by creation time by the Select struct in src/core/trust/impl/sqlite3/store.cpp. Fixed in trust-store (Ubuntu) version 1.1.0+15.04.20150123-0ubuntu1 and trust-store (Ubuntu RTM) version 1.1.0+15.04.20150123~rtm-0ubuntu1.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:canonical:trust-store_\(ubuntu\):*:*:*:*:*:*:*:*
Версия до 1.1.0 (исключая)
cpe:2.3:a:canonical:trust-store_\(ubuntu_rtm\):*:*:*:*:*:*:*:*
Версия до 1.1.0 (исключая)

EPSS

Процентиль: 12%
0.00042
Низкий

5 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-275
CWE-732

Связанные уязвимости

CVSS3: 5
ubuntu
больше 5 лет назад

In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the application will honour incorrect, cached permissions. This is because the cache was not ordered by creation time by the Select struct in src/core/trust/impl/sqlite3/store.cpp. Fixed in trust-store (Ubuntu) version 1.1.0+15.04.20150123-0ubuntu1 and trust-store (Ubuntu RTM) version 1.1.0+15.04.20150123~rtm-0ubuntu1.

github
больше 3 лет назад

In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the application will honour incorrect, cached permissions. This is because the cache was not ordered by creation time by the Select struct in src/core/trust/impl/sqlite3/store.cpp. Fixed in trust-store (Ubuntu) version 1.1.0+15.04.20150123-0ubuntu1 and trust-store (Ubuntu RTM) version 1.1.0+15.04.20150123~rtm-0ubuntu1.

EPSS

Процентиль: 12%
0.00042
Низкий

5 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-275
CWE-732