CVE-2014-7204
published 2014-10-07CVE-2014-7204: jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.28%
90.1th percentile
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | exuberant-ctags | < exuberant-ctags 1:5.9~svn20110310-8 (bookworm) | exuberant-ctags 1:5.9~svn20110310-8 (bookworm) |
| debian | exuberant_ctags | — | — |
| mageia | mageia | — | — |
| mageia | mageia | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_msrc5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2014-7204: NIST NVD Details: https://nvd
vendor_msrc·2021-07-13·CVSS 5.0
CVE-2014-7204 [MEDIUM] CVE-2014-7204: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2014-7204
Mariner: Mariner
[email protected]: [email protected]
Exploit Status: DOS:N/A
Remediation: ctags
Ubuntu
Exuberant Ctags vulnerability
vendor_ubuntu·2014-10-08
CVE-2014-7204 Exuberant Ctags vulnerability
Title: Exuberant Ctags vulnerability
Summary: Exuberant Ctags could be made to consume resources.
It was discovered that Exuberant Ctags incorrectly handled certain minified
js files. An attacker could use this issue to possibly cause Exuberant
Ctags to consume resources, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ctags: possible denial of service
vendor_redhat·2014-03-25·CVSS 5.0
CVE-2014-7204 [MEDIUM] CWE-400 ctags: possible denial of service
ctags: possible denial of service
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: ctags (Red Hat Enterprise Linux 5) - Will not fix
Package: ctags (Red Hat Enterprise Linux 6) - Will not fix
Package: ctags (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-7204: exuberant-ctags - jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of se...
vendor_debian·2014·CVSS 5.0
CVE-2014-7204 [MEDIUM] CVE-2014-7204: exuberant-ctags - jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of se...
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
Scope: local
bookworm: resolved (fixed in 1:5.9~svn20110310-8)
bullseye: resolved (fixed in 1:5.9~svn20110310-8)
forky: resolved (fixed in 1:5.9~svn20110310-8)
sid: resolved (fixed in 1:5.9~svn20110310-8)
trixie: resolved (fixed in 1:5.9~svn20110310-8)
GHSA
GHSA-5p88-49h5-82pm: jscript
ghsa_unreviewed·2022-05-17
CVE-2014-7204 [MEDIUM] GHSA-5p88-49h5-82pm: jscript
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
OSV
CVE-2014-7204: jscript
osv·2014-10-07·CVSS 5.0
CVE-2014-7204 [MEDIUM] CVE-2014-7204: jscript
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
No detection rules found.
http://advisories.mageia.org/MGASA-2014-0415.htmlhttp://sourceforge.net/p/ctags/code/791/http://www.debian.org/security/2014/dsa-3042http://www.mandriva.com/security/advisories?name=MDVSA-2015:178http://www.openwall.com/lists/oss-security/2014/09/29/40http://www.ubuntu.com/usn/USN-2371-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742605http://advisories.mageia.org/MGASA-2014-0415.htmlhttp://sourceforge.net/p/ctags/code/791/http://www.debian.org/security/2014/dsa-3042http://www.mandriva.com/security/advisories?name=MDVSA-2015:178http://www.openwall.com/lists/oss-security/2014/09/29/40http://www.ubuntu.com/usn/USN-2371-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742605
2014-10-07
Published