| Vulnerability Name: | CVE-2014-2029 (CCN-91340) | ||||||||||||||||||||||||||||||||
| Assigned: | 2014-02-19 | ||||||||||||||||||||||||||||||||
| Published: | 2014-02-19 | ||||||||||||||||||||||||||||||||
| Updated: | 2017-10-10 | ||||||||||||||||||||||||||||||||
| Summary: | The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configuration information from v.percona.com. | ||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 8.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
| ||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2014-2029 Source: CCN Type: oss-security: Tue, 18 Feb 2014 CVE Request: Percona Toolkit automatic version check - remote code execution / information leak Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20140219 Re: CVE Request: Percona Toolkit automatic version check - remote code execution / information leak Source: CCN Type: Percona Web site Toolkit Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bugs.launchpad.net/percona-toolkit/+bug/1279502 Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://bugzilla.novell.com/show_bug.cgi?id=864194 Source: XF Type: UNKNOWN percona-toolkit-cve20142029-command-exec(91340) Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-2029 | ||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||