CVE-2014-1422
Summary
| CVE | CVE-2014-1422 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-22 18:15:00 UTC |
| Updated | 2020-08-09 20:36:00 UTC |
| Description | In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the application will honour incorrect, cached permissions. This is because the cache was not ordered by creation time by the Select struct in src/core/trust/impl/sqlite3/store.cpp. Fixed in trust-store (Ubuntu) version 1.1.0+15.04.20150123-0ubuntu1 and trust-store (Ubuntu RTM) version 1.1.0+15.04.20150123~rtm-0ubuntu1. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Canonical | Trust-store Ubuntu | All | All | All | All |
| Application | Canonical | Trust-store Ubuntu Rtm | All | All | All | All |
| Application | Canonical | Trust-store Ubuntu | All | All | All | All |
| Application | Canonical | Trust-store Ubuntu | All | All | All | All |
| Application | Canonical | Trust-store Ubuntu Rtm | All | All | All | All |
| Application | Canonical | Trust-store Ubuntu Rtm | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ~phablet-team/trust-store/trunk : revision 82 | CONFIRM | bazaar.launchpad.net | Patch, Third Party Advisory |
| Bug #1387734 “Location service uses the cached authorization, ev...” : Bugs : location-service package : Ubuntu | CONFIRM | launchpad.net | Exploit, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: David Barth
There are currently no legacy QID mappings associated with this CVE.