CVE-2014-2980
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
28/04/2014
Last modified:
12/04/2025
Description
Tools/gdomap.c in gdomap in GNUstep Base 1.24.6 and earlier, when run in daemon mode, does not properly handle the file descriptor for the logger, which allows remote attackers to cause a denial of service (abort) via an invalid request.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:gnustep:base:*:*:*:*:*:*:*:* | 1.24.6 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://seclists.org/oss-sec/2014/q2/143
- http://seclists.org/oss-sec/2014/q2/152
- http://secunia.com/advisories/58104
- http://svn.gna.org/viewcvs/gnustep/libs/base/trunk/ChangeLog?r1=37756&r2=37755&pathrev=37756
- http://svn.gna.org/viewcvs/gnustep/libs/base/trunk/Tools/gdomap.c?r1=37756&r2=37755&pathrev=37756
- http://www.securityfocus.com/bid/66992
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92688
- https://savannah.gnu.org/bugs/?41751=
- http://seclists.org/oss-sec/2014/q2/143
- http://seclists.org/oss-sec/2014/q2/152
- http://secunia.com/advisories/58104
- http://svn.gna.org/viewcvs/gnustep/libs/base/trunk/ChangeLog?r1=37756&r2=37755&pathrev=37756
- http://svn.gna.org/viewcvs/gnustep/libs/base/trunk/Tools/gdomap.c?r1=37756&r2=37755&pathrev=37756
- http://www.securityfocus.com/bid/66992
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92688
- https://savannah.gnu.org/bugs/?41751=



