cbcvebase.
CVE-2014-0475
published 2014-07-29

CVE-2014-0475: Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand…

medium6.8CVSS 3.1
AVNACMAuNCPIPAP
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianglibc< glibc 2.19-6 (bookworm)glibc 2.19-6 (bookworm)
eglibceglibc>= 0 < 2.19-0ubuntu6.12.19-0ubuntu6.1
eglibceglibc>= 0 < 2.19-0ubuntu6.32.19-0ubuntu6.3
gnuglibc<= 2.19
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc

CVSS provenance

nvd6.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH