CVE-2014-0039

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/02/2014
Last modified:
11/04/2025

Description

Untrusted search path vulnerability in fwsnort before 1.6.4, when not running as root, allows local users to execute arbitrary code via a Trojan horse fwsnort.conf in the current working directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cipherdyne:fwsnort:*:*:*:*:*:*:*:* 1.6.4 (including)
cpe:2.3:a:cipherdyne:fwsnort:0.5:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:0.6:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:0.6.2:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:0.6.3:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:0.6.4:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:0.6.5:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:0.7.0:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:0.8.0:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:0.8.1:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:0.8.2:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:0.9.0:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:1.0:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwsnort:1.0.1:*:*:*:*:*:*:*