VulnerabilityModified
CVE-2014-4168
(1) iodined.c and (2) user.c in iodine before 0.7.0 allows remote attackers to bypass authentication by continuing execution after an error has been triggering.
MEDIUM 5.0EPSS 3.75%
Does this matter?
Lower severity and a low EPSS score (3.75%). Track it; it rarely justifies an emergency change on its own.
Description
(1) iodined.c and (2) user.c in iodine before 0.7.0 allows remote attackers to bypass authentication by continuing execution after an error has been triggering.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.75% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- kryo/iodine
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/59417
- http://www.debian.org/security/2014/dsa-2964
- http://www.openwall.com/lists/oss-security/2014/06/16/5
- http://www.openwall.com/lists/oss-security/2014/06/18/1
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=751834
- https://github.com/yarrick/iodine/blob/b715be5cf3978fbe589b03b09c9398d0d791f850/CHANGELOG
- http://secunia.com/advisories/59417
- http://www.debian.org/security/2014/dsa-2964
- http://www.openwall.com/lists/oss-security/2014/06/16/5
- http://www.openwall.com/lists/oss-security/2014/06/18/1
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=751834
- https://github.com/yarrick/iodine/blob/b715be5cf3978fbe589b03b09c9398d0d791f850/CHANGELOG
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.