CVE-2014-1422 - CVE House
Back to Database
Status published Medium CVE-2014-1422

Location service uses cached authorization even after revocation

Vulnerability Description

In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the application will honour incorrect, cached permissions. This is because the cache was not ordered by creation time by the Select struct in src/core/trust/impl/sqlite3/store.cpp. Fixed in trust-store (Ubuntu) version 1.1.0+15.04.20150123-0ubuntu1 and trust-store (Ubuntu RTM) version 1.1.0+15.04.20150123~rtm-0ubuntu1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-1422

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • David Barth

Affected Vendor

Affected Software

trust-store (Ubuntu), trust-store (Ubuntu RTM)
Vulnerable Versions:
1.1.0

Timeline

Official Publish: July 22nd, 2020
Last Modified: September 17th, 2024
Added to House: July 19th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.