cbcvebase.
CVE-2014-0475
published 2014-07-29

CVE-2014-0475: Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand…

PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.69%
84.3th percentile
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianglibc< glibc 2.19-6 (bookworm)glibc 2.19-6 (bookworm)
eglibceglibc>= 0 < 2.19-0ubuntu6.12.19-0ubuntu6.1
eglibceglibc>= 0 < 2.19-0ubuntu6.32.19-0ubuntu6.3
gnuglibc<= 2.19
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.