CVE-2014-1424
published 2014-11-24CVE-2014-1424: apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors…
PriorityP431medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
1.57%
72.5th percentile
apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apparmor | apparmor | >= 0 < 2.8.95~2430-0ubuntu5.1 | 2.8.95~2430-0ubuntu5.1 |
| canonical | ubuntu | — | — |
| debian | apparmor | — | — |
| ubuntu | apparmor | <= 2.8.94-0ubuntu1.4 | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv6.4MEDIUM
vendor_debian6.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
AppArmor vulnerability
vendor_ubuntu·2014-11-20
CVE-2014-1424 AppArmor vulnerability
Title: AppArmor vulnerability
Summary: apparmor_parser could allow applications that are confined by AppArmor to gain
unintended access to resources.
An AppArmor policy miscompilation flaw was discovered in apparmor_parser. Under
certain circumstances, a malicious application could use this flaw to perform
operations that are not allowed by AppArmor policy. The flaw may also prevent
applications from accessing resources that are allowed by AppArmor policy.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2014-1424: apparmor - apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu ...
vendor_debian·2014·CVSS 6.4
CVE-2014-1424 [MEDIUM] CVE-2014-1424: apparmor - apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu ...
apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-fq7h-8mv4-76qc: apparmor_parser in the apparmor package before 2
ghsa_unreviewed·2022-05-17
CVE-2014-1424 [MEDIUM] GHSA-fq7h-8mv4-76qc: apparmor_parser in the apparmor package before 2
apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."
OSV
CVE-2014-1424: apparmor_parser in the apparmor package before 2
osv·2014-11-24·CVSS 6.4
CVE-2014-1424 [MEDIUM] CVE-2014-1424: apparmor_parser in the apparmor package before 2
apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-11-24
Published