CVE-2014-0039
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/02/2014
Last modified:
11/04/2025
Description
Untrusted search path vulnerability in fwsnort before 1.6.4, when not running as root, allows local users to execute arbitrary code via a Trojan horse fwsnort.conf in the current working directory.
Impact
Base Score 2.0
4.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cipherdyne:fwsnort:*:*:*:*:*:*:*:* | 1.6.4 (including) | |
| cpe:2.3:a:cipherdyne:fwsnort:0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:0.6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:0.6.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:0.6.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:0.6.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:0.6.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:0.7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:0.8.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:0.8.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:0.8.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:0.9.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cipherdyne:fwsnort:1.0.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128188.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128205.html
- http://osvdb.org/102822
- http://seclists.org/oss-sec/2014/q1/221
- http://www.securityfocus.com/bid/65341
- https://github.com/mrash/fwsnort/blob/master/ChangeLog
- https://github.com/mrash/fwsnort/commit/fa977453120cc48e1654f373311f9cac468d3348
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128188.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/128205.html
- http://osvdb.org/102822
- http://seclists.org/oss-sec/2014/q1/221
- http://www.securityfocus.com/bid/65341
- https://github.com/mrash/fwsnort/blob/master/ChangeLog
- https://github.com/mrash/fwsnort/commit/fa977453120cc48e1654f373311f9cac468d3348



