CVE-2014-8119
published 2017-12-29CVE-2014-8119: The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path…
PriorityP428high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.67%
84.2th percentile
The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | netcf | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| netcf_project | netcf | <= 0.2.6 | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rqwf-j354-5q38: The find_ifcfg_path function in netcf before 0
ghsa_unreviewed·2022-05-14
CVE-2014-8119 [HIGH] CWE-20 GHSA-rqwf-j354-5q38: The find_ifcfg_path function in netcf before 0
The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
Red Hat
netcf: augeas path expression injection via interface name
vendor_redhat·2015-03-30·CVSS 7.5
CVE-2014-8119 [HIGH] CWE-643 netcf: augeas path expression injection via interface name
netcf: augeas path expression injection via interface name
The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
A denial of service flaw was found in netcf. A specially crafted interface name could cause an application using netcf (such as the libvirt daemon) to crash.
Debian
CVE-2014-8119: netcf - The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to caus...
vendor_debian·2014·CVSS 7.5
CVE-2014-8119 [HIGH] CVE-2014-8119: netcf - The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to caus...
The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
Scope: local
bullseye: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8119 netcf: augeas path expression injection via interface name [epel-5]
bugzilla·2015-03-30·CVSS 7.5
CVE-2014-8119 [HIGH] CVE-2014-8119 netcf: augeas path expression injection via interface name [epel-5]
CVE-2014-8119 netcf: augeas path expression injection via interface name [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 tracking bug for netcf: see blocks bug l
Bugzilla
CVE-2014-8119 netcf: augeas path expression injection via interface name [fedora-all]
bugzilla·2015-03-30·CVSS 7.5
CVE-2014-8119 [HIGH] CVE-2014-8119 netcf: augeas path expression injection via interface name [fedora-all]
CVE-2014-8119 netcf: augeas path expression injection via interface name [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2014-8119 netcf: augeas path expression injection via interface name
bugzilla·2014-12-09·CVSS 7.5
CVE-2014-8119 [HIGH] CVE-2014-8119 netcf: augeas path expression injection via interface name
CVE-2014-8119 netcf: augeas path expression injection via interface name
A flaw was found in the way the netcf's find_ifcfg_path() function processed certain XPath expressions. An attacker able to supply a specially crafted XML file to an application using netcf could cause that application to crash.
Acknowledgements:
This issue was discovered by Hao Liu of Red Hat.
Discussion:
augeas-devel mailing list thread, discussing lack of ways to safely include untrusted user-supplied input in path strings used in augeas queries:
https://www.redhat.com/archives/augeas-devel/2014-December/msg00000.html
---
Augeas upstream issue that tracks changes required to completely fix this netcf issue:
https://github.com/hercules-team/augeas/pull/198
The changes are:
- Addition of new API - aug_esca
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156571.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157508.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157713.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2248.htmlhttp://www.securityfocus.com/bid/78046https://bugzilla.redhat.com/show_bug.cgi?id=1172176https://pagure.io/netcf/blob/050b05c880a6b343baf86780d94764b1aafece37/f/NEWShttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/156571.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157508.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157713.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2248.htmlhttp://www.securityfocus.com/bid/78046https://bugzilla.redhat.com/show_bug.cgi?id=1172176https://pagure.io/netcf/blob/050b05c880a6b343baf86780d94764b1aafece37/f/NEWS
2017-12-29
Published