CVE-2014-6262
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted third argument to the rrdtool.graph function, aka ZEN-15415, a related issue to CVE-2013-2131.
Múltiples vulnerabilidades de cadena de formato en el módulo de Python en RRDtool, como es usado en Zenoss Core versiones anteriores a 4.2.5 y otros productos, permiten a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (bloqueo de aplicación) por medio de un tercer argumento diseñado en la función rrdtool.graph, también se conoce como ZEN-15415, un problema relacionado con CVE-2013-2131.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-09-05 CVE Reserved
- 2020-02-12 CVE Published
- 2023-07-17 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-134: Use of Externally-Controlled Format String
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.kb.cert.org/vuls/id/449452 | Third Party Advisory | |
https://docs.google.com/spreadsheets/d/1dHAc4PxUbs-4Dxzm1wSCE0sMz5UCMY6SW3PlMHSyuuQ/edit?usp=sharing | Third Party Advisory | |
https://github.com/oetiker/rrdtool-1.x/pull/532 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2020/03/msg00000.html | Mailing List | |
https://lists.debian.org/debian-lts-announce/2020/03/msg00003.html | Mailing List | |
https://www.securityfocus.com/bid/71540 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zenoss Search vendor "Zenoss" | Zenoss Core Search vendor "Zenoss" for product "Zenoss Core" | < 4.2.5 Search vendor "Zenoss" for product "Zenoss Core" and version " < 4.2.5" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
|