Executive Summary

Informations
Name CVE-2014-0595 First vendor Publication 2014-05-08
Vendor Cve Last vendor Modification 2020-02-24

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:H/Au:N/C:P/I:P/A:N)
Cvss Base Score 2.6 Attack Range Local
Cvss Impact Score 4.9 Attack Complexity High
Cvss Expoit Score 1.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

/opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic circumstances by leveraging the granting of the F permission by an administrator.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0595

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:26055
 
Oval ID: oval:org.mitre.oval:def:26055
Title: SUSE-SU-2014:0847-1 -- Security update for novell-qtgui, novell-ui-base
Description: Packages novell-ui-base and novell-qtgui were updated to prevent erroneous rights assignment when a user is granted 'File Scan' rights (F).
Family: unix Class: patch
Reference(s): SUSE-SU-2014:0847-1
CVE-2014-0595
Version: 3
Platform(s): SUSE Linux Enterprise Desktop 11
Product(s): novell-qtgui
novell-ui-base
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 1

Nessus® Vulnerability Scanner

Date Description
2014-06-26 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_novell-ui-201405-140519.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/67144
CONFIRM http://www.novell.com/support/kb/doc.php?id=7014932
SUSE http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00030.html

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
Date Informations
2021-05-04 12:29:37
  • Multiple Updates
2021-04-22 01:35:54
  • Multiple Updates
2020-05-23 00:39:37
  • Multiple Updates
2017-12-22 09:21:07
  • Multiple Updates
2017-01-07 09:25:19
  • Multiple Updates
2014-06-27 13:26:17
  • Multiple Updates
2014-05-08 17:23:05
  • First insertion