Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9471

Опубликовано: 25 фев. 2014
Источник: redhat
CVSS2: 2.6

Описание

The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5coreutilsWill not fix
Red Hat Enterprise Linux 6coreutilsWill not fix
Red Hat Enterprise Linux 7coreutilsWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1167548coreutils: memory corruption flaw in parse_datetime()

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.

nvd
около 11 лет назад

The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.

debian
около 11 лет назад

The parse_datetime function in GNU coreutils allows remote attackers t ...

github
больше 3 лет назад

The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.

suse-cvrf
больше 11 лет назад

Recommended update for coreutils

2.6 Low

CVSS2