Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0475

Опубликовано: 09 июл. 2014
Источник: redhat
CVSS2: 6
EPSS Низкий

Описание

Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_, (2) LANG, or other locale environment variable.

A directory traveral flaw was found in the way glibc loaded locale files. An attacker able to make an application use a specially crafted locale name value (for example, specified in an LC_
environment variable) could possibly use this flaw to execute arbitrary code with the privileges of that application.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1102353glibc: directory traversal in LC_* locale handling

EPSS

Процентиль: 53%
0.00307
Низкий

6 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.

nvd
больше 11 лет назад

Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.

debian
больше 11 лет назад

Multiple directory traversal vulnerabilities in GNU C Library (aka gli ...

github
больше 3 лет назад

Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.

oracle-oval
около 11 лет назад

ELSA-2014-1110: glibc security update (IMPORTANT)

EPSS

Процентиль: 53%
0.00307
Низкий

6 Medium

CVSS2