Back to Database
Status published
Low
CVE-2014-2524
The _rl_tropen function in util.c in GNU readline before 6.3...
Vulnerability Description
The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-2524
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:154
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00037.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1077023
- https://lists.fedoraproject.org/pipermail/package-announce/2014-July/135686.html
- http://seclists.org/oss-sec/2014/q1/587
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:132
- http://advisories.mageia.org/MGASA-2014-0319.html
- http://lists.gnu.org/archive/html/bug-readline/2014-03/msg00057.html
- http://seclists.org/oss-sec/2014/q1/579
More from mageia
View All →CVE-2015-0236
libvirt before 1.2.12 allow remote authenticated users to obtain the...
Low
3.5
CVE-2014-9087
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2,...
High
7.5
CVE-2014-8136
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in...
Low
2.1
CVE-2014-8104
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x...
Medium
6.8
Affected Vendor
mageia
View all reports →Affected Software
mageia, readline, opensuse, fedora
Vulnerable Versions:
3.0, 4.0, 0, 2.1, 2.2, 4.1, 4.2, 4.3, 5.0, 5.1, 5.2, 6.0, 6.1, 6.2, 12.3, 13.1, 20
Timeline
Official Publish:
August 20th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.