Vulnerability Name: | CVE-2014-2387 (CCN-91992) | ||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2014-03-13 | ||||||||||||||||||||||||||||||||||||||||||||
Published: | 2014-03-13 | ||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2019-12-19 | ||||||||||||||||||||||||||||||||||||||||||||
Summary: | Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities | ||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)
| ||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 4.4 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:U/RC:UR)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:U/RC:UR)
| ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-668 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-2387 Source: CCN Type: SA57374 pen "webfile.html" Insecure Temporary File Security Issue Source: CCN Type: Pen Web site Pen Source: MISC Type: Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2014/03/13/5 Source: MISC Type: Mailing List http://www.openwall.com/lists/oss-security/2014/03/14/2 Source: CCN Type: BID-66214 Pen 'penctl.cgi' Multiple Insecure Temporary File Creation Vulnerabilities Source: MISC Type: Third Party Advisory, VDB Entry http://www.securityfocus.com/bid/66214 Source: CCN Type: Red Hat Bugzilla Bug 1057746 CVE-2014-0019 socat: PROXY-CONNECT address overflow Source: CCN Type: Red Hat Bugzilla Bug 1076049 CVE-2014-2387 pen: insecure temporary file use flaws Source: MISC Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-2387 Source: MISC Type: Issue Tracking, Third Party Advisory https://bugzilla.suse.com/show_bug.cgi?id=CVE-2014-2387 Source: MISC Type: Third Party Advisory, VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/91992 Source: XF Type: UNKNOWN pen-cve20142387-symlink(91992) Source: MISC Type: Third Party Advisory https://security-tracker.debian.org/tracker/CVE-2014-2387 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: ![]() | ||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
BACK |