CVE-2014-8990
published 2014-12-05CVE-2014-8990: default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
PriorityP352high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.24%
91.7th percentile
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | lsyncd | < lsyncd 2.1.5-2 (bookworm) | lsyncd 2.1.5-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| lsyncd_project | lsyncd | <= 2.1.5 | — |
| lsyncd_project | lsyncd | >= 0 < 2.1.5-2 | 2.1.5-2 |
| lsyncd_project | lsyncd | >= 0 < 2.1.5-2 | 2.1.5-2 |
| lsyncd_project | lsyncd | >= 0 < 2.1.5-2 | 2.1.5-2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2jg7-cr9w-6gw3: default-rsyncssh
ghsa_unreviewed·2022-05-17
CVE-2014-8990 [HIGH] CWE-77 GHSA-2jg7-cr9w-6gw3: default-rsyncssh
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
OSV
CVE-2014-8990: default-rsyncssh
osv·2014-12-05·CVSS 7.5
CVE-2014-8990 [HIGH] CVE-2014-8990: default-rsyncssh
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
Debian
CVE-2014-8990: lsyncd - default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to exec...
vendor_debian·2014·CVSS 7.5
CVE-2014-8990 [HIGH] CVE-2014-8990: lsyncd - default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to exec...
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
Scope: local
bookworm: resolved (fixed in 2.1.5-2)
bullseye: resolved (fixed in 2.1.5-2)
sid: resolved (fixed in 2.1.5-2)
trixie: resolved (fixed in 2.1.5-2)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145114.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145131.htmlhttp://secunia.com/advisories/62321http://www.debian.org/security/2015/dsa-3130http://www.openwall.com/lists/oss-security/2014/11/19/1http://www.openwall.com/lists/oss-security/2014/11/20/5http://www.securityfocus.com/bid/71179https://github.com/axkibe/lsyncd/commit/18f02ad013b41a72753912155ae2ba72f2a53e52https://github.com/axkibe/lsyncd/commit/e6016b3748370878778b8f0b568d5281cc248aa4https://github.com/axkibe/lsyncd/issues/220https://security.gentoo.org/glsa/201702-05http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145114.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145131.htmlhttp://secunia.com/advisories/62321http://www.debian.org/security/2015/dsa-3130http://www.openwall.com/lists/oss-security/2014/11/19/1http://www.openwall.com/lists/oss-security/2014/11/20/5http://www.securityfocus.com/bid/71179https://github.com/axkibe/lsyncd/commit/18f02ad013b41a72753912155ae2ba72f2a53e52https://github.com/axkibe/lsyncd/commit/e6016b3748370878778b8f0b568d5281cc248aa4https://github.com/axkibe/lsyncd/issues/220https://security.gentoo.org/glsa/201702-05
2014-12-05
Published