CVE-2014-1424Apparmor vulnerability

CWE-2646 documents6 sources
Severity
6.4MEDIUMNVD
EPSS
0.4%
top 42.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 24
Latest updateMay 17

Description

apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages3 packages

NVDubuntu/apparmor2.8.94-0ubuntu1.4
Ubuntuapparmor/apparmor< 2.8.95~2430-0ubuntu5.1
NVDcanonical/ubuntu14.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fq7h-8mv4-76qc: apparmor_parser in the apparmor package before 22022-05-17
CVEList
CVE-2014-1424: apparmor_parser in the apparmor package before 22014-11-24
OSV
CVE-2014-1424: apparmor_parser in the apparmor package before 22014-11-24

📋Vendor Advisories

2
Ubuntu
AppArmor vulnerability2014-11-20
Debian
CVE-2014-1424: apparmor - apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu ...2014
CVE-2014-1424 — Ubuntu Apparmor vulnerability | cvebase