← Back

CVE-2014-8517

nvd nist
Published: Nov 17, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.

Affected (25)

Products: Apple: Mac Os X · Netbsd: Netbsd
1 product
Mac Os X
1 product
Netbsd
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 10.10.0
Version 10.10.1
Version 10.8.5
Version 10.9.5
Configuration B
21 vulnerable
Vulnerable SoftwareAffected Versions
Netbsd
Version 5.1.1
Version 5.1.2
Version 5.1.3
Version 5.1.4
Version 5.1
Version 5.2.1
Version 5.2.2
Version 5.2
Version 6.0.1
Version 6.0.2
Version 6.0.3
Version 6.0.4
Version 6.0.5
Version 6.0.6
Version 6.0
Version 6.1.1
Version 6.1.2
Version 6.1.3
Version 6.1.4
Version 6.1.5
Version 6.1

References (20)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.