Back to Database
Status published
Critical
CVE-2014-5009
Snoopy allows remote attackers to execute arbitrary commands. NOTE:...
Vulnerability Description
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-5009
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.openwall.com/lists/oss-security/2014/07/09/11
- http://www.securityfocus.com/bid/68783
- http://www.openwall.com/lists/oss-security/2014/07/18/2
- http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?r1=1.28&r2=1.29
- http://www.openwall.com/lists/oss-security/2014/07/16/10
- https://www-01.ibm.com/support/docview.wss?uid=isg3T1024264
- http://rhn.redhat.com/errata/RHSA-2017-0212.html
- http://rhn.redhat.com/errata/RHSA-2017-0213.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1121497
- https://github.com/cogdog/feed2js/pull/12#issuecomment-48283706
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94738
- http://rhn.redhat.com/errata/RHSA-2017-0214.html
- http://rhn.redhat.com/errata/RHSA-2017-0211.html
More from snoopy
View All →CVE-2014-5008
Snoopy allows remote attackers to execute arbitrary commands....
Critical
9.8
CVE-2009-0502
Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as...
Medium
4.3
CVE-2008-7313
The _httpsrequest function in Snoopy allows remote attackers to execute...
Critical
9.8
CVE-2005-3330
The _httpsrequest function in Snoopy 1.2, as used in products...
High
7.5
Affected Vendor
snoopy
View all reports →Affected Software
snoopy, openstack, nagios
Vulnerable Versions:
5.0, 6.0, 0
Timeline
Official Publish:
March 31st, 2017
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.