CVE-2014-2524

The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
Affected Products (NVD)
VendorProductVersion
mageiamageia
3.0
mageiamageia
4.0
gnureadline
𝑥
≤ 6.3
gnureadline
2.1
gnureadline
2.2
gnureadline
4.0
gnureadline
4.1
gnureadline
4.2
gnureadline
4.2:a
gnureadline
4.3
gnureadline
5.0
gnureadline
5.1
gnureadline
5.2
gnureadline
6.0
gnureadline
6.1
gnureadline
6.2
opensuseopensuse
12.3
opensuseopensuse
13.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
readline6
lucid
ignored
precise
ignored
quantal
ignored
saucy
ignored
trusty
ignored
utopic
ignored
vivid
ignored
wily
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
bash
suse enterprise desktop 15
4.4-7.14
fixed
suse enterprise desktop 15 SP1
4.4-9.7.1
fixed
suse enterprise sap 12 SP5
4.3-83.23.1
fixed
suse enterprise sap 15
4.4-7.14
fixed
suse enterprise sap 15 SP1
4.4-9.7.1
fixed
suse enterprise server 12
4.2-75.2
fixed
suse enterprise server 12 SP1
4.2-75.2
fixed
suse enterprise server 12 SP5
4.3-83.23.1
fixed
suse enterprise server 15
4.4-7.14
fixed
suse enterprise server 15 SP1
4.4-9.7.1
fixed
bash-devel
suse enterprise desktop 15
4.4-7.14
fixed
suse enterprise desktop 15 SP1
4.4-9.7.1
fixed
suse enterprise sap 15
4.4-7.14
fixed
suse enterprise sap 15 SP1
4.4-9.7.1
fixed
suse enterprise server 15
4.4-7.14
fixed
suse enterprise server 15 SP1
4.4-9.7.1
fixed
bash-doc
suse enterprise desktop 15
4.4-7.14
fixed
suse enterprise desktop 15 SP1
4.4-9.7.1
fixed
suse enterprise sap 12 SP5
4.3-83.23.1
fixed
suse enterprise sap 15
4.4-7.14
fixed
suse enterprise sap 15 SP1
4.4-9.7.1
fixed
suse enterprise server 12
4.2-75.2
fixed
suse enterprise server 12 SP1
4.2-75.2
fixed
suse enterprise server 12 SP5
4.3-83.23.1
fixed
suse enterprise server 15
4.4-7.14
fixed
suse enterprise server 15 SP1
4.4-9.7.1
fixed
bash-lang
suse enterprise desktop 15
4.4-7.14
fixed
suse enterprise desktop 15 SP1
4.4-9.7.1
fixed
suse enterprise sap 15
4.4-7.14
fixed
suse enterprise sap 15 SP1
4.4-9.7.1
fixed
suse enterprise server 15
4.4-7.14
fixed
suse enterprise server 15 SP1
4.4-9.7.1
fixed
crash
suse enterprise desktop 15
7.2.1-1.22
fixed
suse enterprise desktop 15 SP1
7.2.1-7.15
fixed
suse enterprise desktop 15 SP2
7.2.8-16.19
fixed
suse enterprise desktop 15 SP3
7.2.9-21.4
fixed
suse enterprise desktop 15 SP4
7.3.0-150400.1.61
fixed
suse enterprise desktop 15 SP5
7.3.1-150500.3.4
fixed
suse enterprise desktop 15 SP6
8.0.4-150600.2.13
fixed
suse enterprise desktop 15 SP7
8.0.4-150700.6.29
fixed
suse enterprise sap 12 SP5
7.2.1-6.42
fixed
suse enterprise sap 15
7.2.1-1.22
fixed
suse enterprise sap 15 SP1
7.2.1-7.15
fixed
suse enterprise sap 15 SP2
7.2.8-16.19
fixed
suse enterprise sap 15 SP3
7.2.9-21.4
fixed
suse enterprise sap 15 SP4
7.3.0-150400.1.61
fixed
suse enterprise sap 15 SP5
7.3.1-150500.3.4
fixed
suse enterprise sap 15 SP6
8.0.4-150600.2.13
fixed
suse enterprise sap 15 SP7
8.0.4-150700.6.29
fixed
suse enterprise server 12 SP5
7.2.1-6.42
fixed
suse enterprise server 15
7.2.1-1.22
fixed
suse enterprise server 15 SP1
7.2.1-7.15
fixed
suse enterprise server 15 SP2
7.2.8-16.19
fixed
suse enterprise server 15 SP3
7.2.9-21.4
fixed
suse enterprise server 15 SP4
7.3.0-150400.1.61
fixed
suse enterprise server 15 SP5
7.3.1-150500.3.4
fixed
suse enterprise server 15 SP6
8.0.4-150600.2.13
fixed
suse enterprise server 15 SP7
8.0.4-150700.6.29
fixed
crash-devel
suse enterprise desktop 15
7.2.1-1.22
fixed
suse enterprise desktop 15 SP1
7.2.1-7.15
fixed
suse enterprise desktop 15 SP2
7.2.8-16.19
fixed
suse enterprise desktop 15 SP3
7.2.9-21.4
fixed
suse enterprise desktop 15 SP4
7.3.0-150400.1.61
fixed
suse enterprise desktop 15 SP5
7.3.1-150500.3.4
fixed
suse enterprise desktop 15 SP6
8.0.4-150600.2.13
fixed
suse enterprise desktop 15 SP7
8.0.4-150700.6.29
fixed
suse enterprise sap 15
7.2.1-1.22
fixed
suse enterprise sap 15 SP1
7.2.1-7.15
fixed
suse enterprise sap 15 SP2
7.2.8-16.19
fixed
suse enterprise sap 15 SP3
7.2.9-21.4
fixed
suse enterprise sap 15 SP4
7.3.0-150400.1.61
fixed
suse enterprise sap 15 SP5
7.3.1-150500.3.4
fixed
suse enterprise sap 15 SP6
8.0.4-150600.2.13
fixed
suse enterprise sap 15 SP7
8.0.4-150700.6.29
fixed
suse enterprise server 15
7.2.1-1.22
fixed
suse enterprise server 15 SP1
7.2.1-7.15
fixed
suse enterprise server 15 SP2
7.2.8-16.19
fixed
suse enterprise server 15 SP3
7.2.9-21.4
fixed
suse enterprise server 15 SP4
7.3.0-150400.1.61
fixed
suse enterprise server 15 SP5
7.3.1-150500.3.4
fixed
suse enterprise server 15 SP6
8.0.4-150600.2.13
fixed
suse enterprise server 15 SP7
8.0.4-150700.6.29
fixed
crash-trace
suse enterprise desktop 15 SP5
7.3.1-150500.3.4
fixed
suse enterprise sap 15 SP5
7.3.1-150500.3.4
fixed
suse enterprise server 15 SP5
7.3.1-150500.3.4
fixed
libreadline6
suse enterprise sap 12 SP5
6.3-83.23.1
fixed
suse enterprise server 12
6.2-75.2
fixed
suse enterprise server 12 SP1
6.2-75.2
fixed
suse enterprise server 12 SP5
6.3-83.23.1
fixed
libreadline6-32bit
suse enterprise sap 12 SP5
6.3-83.23.1
fixed
suse enterprise server 12
6.2-75.2
fixed
suse enterprise server 12 SP1
6.2-75.2
fixed
suse enterprise server 12 SP5
6.3-83.23.1
fixed
libreadline7
suse enterprise desktop 15
7.0-7.14
fixed
suse enterprise desktop 15 SP1
7.0-9.7.1
fixed
suse enterprise sap 15
7.0-7.14
fixed
suse enterprise sap 15 SP1
7.0-9.7.1
fixed
suse enterprise server 15
7.0-7.14
fixed
suse enterprise server 15 SP1
7.0-9.7.1
fixed
readline-devel
suse enterprise desktop 15
7.0-7.14
fixed
suse enterprise desktop 15 SP1
7.0-9.7.1
fixed
suse enterprise sap 15
7.0-7.14
fixed
suse enterprise sap 15 SP1
7.0-9.7.1
fixed
suse enterprise server 15
7.0-7.14
fixed
suse enterprise server 15 SP1
7.0-9.7.1
fixed
readline-doc
suse enterprise desktop 15
7.0-7.14
fixed
suse enterprise desktop 15 SP1
7.0-9.7.1
fixed
suse enterprise sap 12 SP5
6.3-83.23.1
fixed
suse enterprise sap 15
7.0-7.14
fixed
suse enterprise sap 15 SP1
7.0-9.7.1
fixed
suse enterprise server 12
6.2-75.2
fixed
suse enterprise server 12 SP1
6.2-75.2
fixed
suse enterprise server 12 SP5
6.3-83.23.1
fixed
suse enterprise server 15
7.0-7.14
fixed
suse enterprise server 15 SP1
7.0-9.7.1
fixed