Vulnerability Name: | CVE-2014-3741 (CCN-93167) | ||||||||||||||||||||
Assigned: | 2014-05-13 | ||||||||||||||||||||
Published: | 2014-05-13 | ||||||||||||||||||||
Updated: | 2017-11-21 | ||||||||||||||||||||
Summary: | The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in the lpr command. | ||||||||||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
| ||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-77 | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-3741 Source: CCN Type: oss-security Mailing List, Tue 13 May 2014 CVE request: various NodeJS module vulnerabilities Source: CCN Type: oss-security Mailing List, Wed 14 May 2014 Re: CVE request: various NodeJS module vulnerabilities Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20140513 CVE request: various NodeJS module vulnerabilities Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20140514 Re: CVE request: various NodeJS module vulnerabilities Source: CCN Type: BID-67346 node-printer 'printDirect()' Function Remote Command Injection Vulnerability Source: XF Type: UNKNOWN nodeprinter-cve20143741-command-exec(93167) Source: CCN Type: node.js Web page node-printer Source: CONFIRM Type: Issue Tracking, Patch https://github.com/tojocky/node-printer/commit/e001e38738c17219a1d9dd8c31f7d82b9c0013c7 Source: MISC Type: Third Party Advisory https://nodesecurity.io/advisories/printer_potential_command_injection Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-3741 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |