CVE-2014-7204Uncontrolled Resource Consumption in Exuberant-ctags

Severity
5.0MEDIUMNVD
EPSS
2.8%
top 13.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 7
Latest updateMay 17

Description

jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages5 packages

debiandebian/exuberant-ctags< exuberant-ctags 1:5.9~svn20110310-8 (bookworm)
NVDmageia/mageia3.0, 4.0+1

Also affects: Debian Linux 7.0, Ubuntu Linux 12.04, 14.04

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5p88-49h5-82pm: jscript2022-05-17
OSV
CVE-2014-7204: jscript2014-10-07

💥Exploits & PoCs

1
Exploit-DB
Hikvision DVR - RTSP Request Remote Code Execution (Metasploit)2014-11-24

📋Vendor Advisories

4
Microsoft
CVE-2014-7204: NIST NVD Details: https://nvd2021-07-13
Ubuntu
Exuberant Ctags vulnerability2014-10-08
Red Hat
ctags: possible denial of service2014-03-25
Debian
CVE-2014-7204: exuberant-ctags - jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of se...2014

💬Community

1
Bugzilla
CVE-2014-7204 ctags: possible denial of service2014-09-29