Lucene search

K
nvd[email protected]NVD:CVE-2014-2972
HistorySep 04, 2014 - 5:55 p.m.

CVE-2014-2972

2014-09-0417:55:05
CWE-189
web.nvd.nist.gov

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.

Affected configurations

NVD
Node
eximeximRange4.82.1
OR
eximeximMatch4.00
OR
eximeximMatch4.01
OR
eximeximMatch4.02
OR
eximeximMatch4.03
OR
eximeximMatch4.04
OR
eximeximMatch4.05
OR
eximeximMatch4.10
OR
eximeximMatch4.11
OR
eximeximMatch4.12
OR
eximeximMatch4.14
OR
eximeximMatch4.20
OR
eximeximMatch4.21
OR
eximeximMatch4.22
OR
eximeximMatch4.23
OR
eximeximMatch4.24
OR
eximeximMatch4.30
OR
eximeximMatch4.31
OR
eximeximMatch4.32
OR
eximeximMatch4.33
OR
eximeximMatch4.34
OR
eximeximMatch4.40
OR
eximeximMatch4.41
OR
eximeximMatch4.42
OR
eximeximMatch4.43
OR
eximeximMatch4.44
OR
eximeximMatch4.50
OR
eximeximMatch4.51
OR
eximeximMatch4.52
OR
eximeximMatch4.53
OR
eximeximMatch4.54
OR
eximeximMatch4.60
OR
eximeximMatch4.61
OR
eximeximMatch4.62
OR
eximeximMatch4.63
OR
eximeximMatch4.64
OR
eximeximMatch4.65
OR
eximeximMatch4.66
OR
eximeximMatch4.67
OR
eximeximMatch4.68
OR
eximeximMatch4.69
OR
eximeximMatch4.70
OR
eximeximMatch4.71
OR
eximeximMatch4.72
OR
eximeximMatch4.73
OR
eximeximMatch4.74
OR
eximeximMatch4.75
OR
eximeximMatch4.76
OR
eximeximMatch4.77
OR
eximeximMatch4.80
OR
eximeximMatch4.80.1
OR
eximeximMatch4.82

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%