Command Injection - CVE-2014-8990

 

Command Injection - CVE-2014-8990

Published: December 5, 2014 / Updated: August 3, 2020


Vulnerability identifier: #VU33063
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-8990
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.


Affected software

Gentoo Linux
Fedora

yaml (Alpine package)
qemu (Alpine package)
docker (Alpine package)
zoneminder (Alpine package)
munin (Alpine package)
lsyncd (Alpine package)
graphviz (Alpine package)
lsyncd

How to mitigate CVE-2014-8990

Install update from vendor's website.

yaml (Alpine package) - addressed in versions 0.1.6-r1, 0.1.7-r0
qemu (Alpine package) - addressed in versions 1.6.2-r4, 2.1.2-r1, 2.1.2-r2, 2.5.0-r0
docker (Alpine package) - update to 1.12.6-r0
zoneminder (Alpine package) - update to 1.30.2-r0
munin (Alpine package) - update to 2.0.33-r0
lsyncd (Alpine package) - update to 2.1.5-r3
graphviz (Alpine package) - update to 2.40.1-r0
lsyncd - addressed in versions 2.1.4-4.el5.1.1, 2.1.4-4.el6.1.1, 2.1.5-0.el6, 2.1.5-6.el7, 2.1.5-6.fc21
- update to 2.11-8ubuntu4

External References

Related Security Bulletins