CVE-2014-2079
Summary
| CVE | CVE-2014-2079 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-16 14:29:00 UTC |
| Updated | 2018-09-15 12:31:00 UTC |
| Description | X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | X File Explorer Project | X File Explorer | 1.32.5 | All | All | All |
| Application | X File Explorer Project | X File Explorer | 1.32.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| X File Explorer 'FilePanel::onCmdNewFile' Function Access Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| oss-security - Re: xfe: directory masks ignored when creating new files on Samba and NFS | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| #739536 - xfe: CVE-2014-2079: directory masks ignored when creating new files on Samba and NFS - Debian Bug report logs | CONFIRM | bugs.debian.org | Mailing List, Patch, Third Party Advisory |
| 1069066 – (CVE-2014-2079) CVE-2014-2079 xfe: directory masks ignored when creating new files on Samba and NFS | CONFIRM | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.