CVE-2014-9471
published 2015-01-16CVE-2014-9471: The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.09%
93.5th percentile
The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | coreutils | < coreutils 8.23-1 (bookworm) | coreutils 8.23-1 (bookworm) |
| gnu | coreutils | < 8.23 | 8.23 |
| gnu | coreutils | >= 0 < 8.23-1 | 8.23-1 |
| gnu | coreutils | >= 0 < 8.23-1 | 8.23-1 |
| gnu | coreutils | >= 0 < 8.23-1 | 8.23-1 |
| gnu | coreutils | >= 0 < 8.23-1 | 8.23-1 |
| gnu | coreutils | >= 0 < 8.21-1ubuntu5.1 | 8.21-1ubuntu5.1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
coreutils vulnerabilities
vendor_ubuntu·2015-01-14·CVSS 4.4
CVE-2009-4135 [MEDIUM] coreutils vulnerabilities
Title: coreutils vulnerabilities
Summary: date and touch could be made to crash or run programs if they
handled specially crafted input.
It was discovered that the distcheck rule in dist-check.mk in GNU
coreutils allows local users to gain privileges via a symlink attack
on a directory tree under /tmp. This issue only affected Ubuntu 10.04 LTS.
(CVE-2009-4135)
Bertrand Jacquin and Fiedler Roman discovered date and touch incorrectly
handled user-supplied input. An attacker could possibly use this to cause
a denial of service or potentially execute code. (CVE-2014-9471)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
coreutils: memory corruption flaw in parse_datetime()
vendor_redhat·2014-02-25·CVSS 7.5
CVE-2014-9471 [HIGH] CWE-20 coreutils: memory corruption flaw in parse_datetime()
coreutils: memory corruption flaw in parse_datetime()
The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: coreutils (Red Hat Enterprise Linux 5) - Will not fix
Package: coreutils (Red Hat Enterprise Linux 6) - Will not fix
Package: coreutils (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-9471: coreutils - The parse_datetime function in GNU coreutils allows remote attackers to cause a ...
vendor_debian·2014·CVSS 7.5
CVE-2014-9471 [HIGH] CVE-2014-9471: coreutils - The parse_datetime function in GNU coreutils allows remote attackers to cause a ...
The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.
Scope: local
bookworm: resolved (fixed in 8.23-1)
bullseye: resolved (fixed in 8.23-1)
forky: resolved (fixed in 8.23-1)
sid: resolved (fixed in 8.23-1)
trixie: resolved (fixed in 8.23-1)
GHSA
GHSA-vg73-g8m4-q62r: The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a cra
ghsa_unreviewed·2022-05-13
CVE-2014-9471 [HIGH] GHSA-vg73-g8m4-q62r: The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a cra
The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.
OSV
CVE-2014-9471: The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a cra
osv·2015-01-16·CVSS 7.5
CVE-2014-9471 [HIGH] CVE-2014-9471: The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a cra
The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.
OSV
coreutils vulnerabilities
osv·2015-01-14·CVSS 4.4
CVE-2009-4135 [MEDIUM] coreutils vulnerabilities
coreutils vulnerabilities
It was discovered that the distcheck rule in dist-check.mk in GNU
coreutils allows local users to gain privileges via a symlink attack
on a directory tree under /tmp. This issue only affected Ubuntu 10.04 LTS.
(CVE-2009-4135)
Bertrand Jacquin and Fiedler Roman discovered date and touch incorrectly
handled user-supplied input. An attacker could possibly use this to cause
a denial of service or potentially execute code. (CVE-2014-9471)
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0029.htmlhttp://debbugs.gnu.org/cgi/bugreport.cgi?bug=16872http://secunia.com/advisories/62226http://ubuntu.com/usn/usn-2473-1http://www.mandriva.com/security/advisories?name=MDVSA-2015:179http://www.openwall.com/lists/oss-security/2014/11/25/1http://www.openwall.com/lists/oss-security/2014/11/25/4http://www.openwall.com/lists/oss-security/2015/01/03/11https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=766147https://security.gentoo.org/glsa/201612-22http://advisories.mageia.org/MGASA-2015-0029.htmlhttp://debbugs.gnu.org/cgi/bugreport.cgi?bug=16872http://secunia.com/advisories/62226http://ubuntu.com/usn/usn-2473-1http://www.mandriva.com/security/advisories?name=MDVSA-2015:179http://www.openwall.com/lists/oss-security/2014/11/25/1http://www.openwall.com/lists/oss-security/2014/11/25/4http://www.openwall.com/lists/oss-security/2015/01/03/11https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=766147https://security.gentoo.org/glsa/201612-22
2015-01-16
Published