CVE-2014-9114

CWE-77Command Injection8 documents7 sources
Severity
7.8HIGH
EPSS
0.1%
top 67.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateMay 13

Description

Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debianutil-linux< 2.25.2-4+3
NVDkernel/util-linux2.24.2-1
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Fedora 20, 21

Patches

🔴Vulnerability Details

3
GHSA
GHSA-g7m2-8cqp-hf7v: Blkid in util-linux before 22022-05-13
CVEList
CVE-2014-9114: Blkid in util-linux before 22017-03-31
OSV
CVE-2014-9114: Blkid in util-linux before 22017-03-31

📋Vendor Advisories

2
Red Hat
util-linux: command injection flaw in blkid2014-11-26
Debian
CVE-2014-9114: util-linux - Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code...2014

💬Community

2
Bugzilla
CVE-2014-9114 util-linux: command injection flaw in blkid [fedora-all]2014-11-27
Bugzilla
CVE-2014-9114 util-linux: command injection flaw in blkid2014-11-27
CVE-2014-9114 (HIGH CVSS 7.8) | Blkid in util-linux before 2.26rc-1 | cvebase.io