CVE-2014-2029
Description
The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configuration information from v.percona.com.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
CVE-2014-2029 NameCVE-2014-2029 DescriptionThe automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configuration information from v.percona.com. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE…
CVE-2014-2029
| Name | CVE-2014-2029 |
| Description | The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configuration information from v.percona.com. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 740846, 751377 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| percona-toolkit (PTS) | bookworm, bullseye, trixie | 3.2.1-1 | fixed |
| forky, sid | 3.7.1-4 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| percona-toolkit | source | wheezy | (not affected) | |||
| percona-toolkit | source | (unstable) | 2.2.7-1~dfsg1 | 740846 | ||
| percona-xtrabackup | source | (unstable) | 2.2.3-1 | 751377 |
Notes
[wheezy] - percona-toolkit <not-affected> (version-check introduced in 2.1.4)
Apply commands
[wheezy] - percona-toolkit <not-affected> (version-check introduced in 2.1.4)
OS impact
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 2.2.7-1~dfsg1 |
| sid | Fixed | 2.2.7-1~dfsg1 |
| forky | Fixed | 2.2.7-1~dfsg1 |
| bullseye | Fixed | 2.2.7-1~dfsg1 |
| bookworm | Fixed | 2.2.7-1~dfsg1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| percona | toolkit | 2.1 | |
References
CWEs
CWE-200
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.