CVE-2014-2079
published 2018-07-16CVE-2014-2079: X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use…
PriorityP426medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.40%
32.8th percentile
X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xfe | < xfe 1.37-2 (bookworm) | xfe 1.37-2 (bookworm) |
| x_file_explorer_project | x_file_explorer | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2014-2079: xfe - X File Explorer (aka xfe) might allow local users to bypass intended access rest...
vendor_debian·2014·CVSS 5.5
CVE-2014-2079 [MEDIUM] CVE-2014-2079: xfe - X File Explorer (aka xfe) might allow local users to bypass intended access rest...
X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.
Scope: local
bookworm: resolved (fixed in 1.37-2)
bullseye: resolved (fixed in 1.37-2)
forky: resolved (fixed in 1.37-2)
sid: resolved (fixed in 1.37-2)
trixie: resolved (fixed in 1.37-2)
GHSA
GHSA-rgg2-xp4r-28h4: X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to u
ghsa_unreviewed·2022-05-14
CVE-2014-2079 [MEDIUM] GHSA-rgg2-xp4r-28h4: X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to u
X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.
OSV
CVE-2014-2079: X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to u
osv·2018-07-16·CVSS 5.5
CVE-2014-2079 [MEDIUM] CVE-2014-2079: X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to u
X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2014/02/24/5http://www.securityfocus.com/bid/65748https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=739536https://bugzilla.redhat.com/show_bug.cgi?id=1069066https://exchange.xforce.ibmcloud.com/vulnerabilities/91519http://www.openwall.com/lists/oss-security/2014/02/24/5http://www.securityfocus.com/bid/65748https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=739536https://bugzilla.redhat.com/show_bug.cgi?id=1069066https://exchange.xforce.ibmcloud.com/vulnerabilities/91519
2018-07-16
Published