Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-7817

Опубликовано: 20 нояб. 2014
Источник: redhat
CVSS2: 3.6
EPSS Низкий

Описание

The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((...))".

It was found that the wordexp() function would perform command substitution even when the WRDE_NOCMD flag was specified. An attacker able to provide specially crafted input to an application using the wordexp() function, and not sanitizing the input correctly, could potentially use this flaw to execute arbitrary commands with the credentials of the user running that application.

Отчет

This issue affects the version of glibc package as shipped with Red Hat Enterprise Linux 5, 6 and 7. Red Hat Product Security has rated this issue as having Moderate security impact. Red Hat Enterprise Linux 5 is now in Extended Life Cycle phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5glibcWill not fix
Red Hat Enterprise Linux 6glibcFixedRHSA-2015:001607.01.2015
Red Hat Enterprise Linux 7glibcFixedRHSA-2014:202318.12.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-440
https://bugzilla.redhat.com/show_bug.cgi?id=1157689glibc: command execution in wordexp() with WRDE_NOCMD specified

EPSS

Процентиль: 38%
0.00165
Низкий

3.6 Low

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".

nvd
почти 11 лет назад

The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".

debian
почти 11 лет назад

The wordexp function in GNU C Library (aka glibc) 2.21 does not enforc ...

github
больше 3 лет назад

The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".

oracle-oval
больше 10 лет назад

ELSA-2014-2023: glibc security and bug fix update (MODERATE)

EPSS

Процентиль: 38%
0.00165
Низкий

3.6 Low

CVSS2