CVE-2014-2079

unknown
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk

Description

X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2014-2079 NameCVE-2014-2079 DescriptionX File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub…

CVE-2014-2079

NameCVE-2014-2079
DescriptionX File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs739536

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xfe (PTS)bullseye1.43.2-3fixed
bookworm1.45-2fixed
trixie2.0.1-2fixed
forky2.1.6-1fixed
sid2.1.7-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xfesource(unstable)1.37-2739536

Notes

[wheezy] - xfe <no-dsa> (Minor issue)
[squeeze] - xfe <no-dsa> (Minor issue)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[wheezy] - xfe <no-dsa> (Minor issue)[squeeze] - xfe <no-dsa> (Minor issue)

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1.37-2
sid Fixed 1.37-2
forky Fixed 1.37-2
bullseye Fixed 1.37-2
bookworm Fixed 1.37-2

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.