VulnerabilityModified
CVE-2014-3980
libfep 0.0.5 before 0.1.0 does not properly use UNIX domain sockets in the abstract namespace, which allows local users to gain privileges via unspecified vectors.
MEDIUM 4.6EPSS 0.37%
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
libfep 0.0.5 before 0.1.0 does not properly use UNIX domain sockets in the abstract namespace, which allows local users to gain privileges via unspecified vectors.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.37% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- daiki ueno/libfep
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2014/06/05/16
- http://www.openwall.com/lists/oss-security/2014/06/06/11
- http://www.securityfocus.com/bid/67903
- https://github.com/ueno/libfep/commit/293d9d3f
- http://www.openwall.com/lists/oss-security/2014/06/05/16
- http://www.openwall.com/lists/oss-security/2014/06/06/11
- http://www.securityfocus.com/bid/67903
- https://github.com/ueno/libfep/commit/293d9d3f
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.