Candidate: CVE-2014-0039 PublicDate: 2014-02-08 00:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0039 https://github.com/mrash/fwsnort/commit/fa977453120cc48e1654f373311f9cac468d3348 Description: Untrusted search path vulnerability in fwsnort before 1.6.4, when not running as root, allows local users to execute arbitrary code via a Trojan horse fwsnort.conf in the current working directory. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737495 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_fwsnort: upstream_fwsnort: needs-triage lucid_fwsnort: ignored (reached end-of-life) precise_fwsnort: ignored (reached end-of-life) precise/esm_fwsnort: DNE (precise was needed) quantal_fwsnort: ignored (reached end-of-life) saucy_fwsnort: ignored (reached end-of-life) trusty_fwsnort: ignored (reached end-of-life) trusty/esm_fwsnort: DNE (trusty was needed) utopic_fwsnort: ignored (reached end-of-life) vivid_fwsnort: ignored (reached end-of-life) vivid/stable-phone-overlay_fwsnort: DNE vivid/ubuntu-core_fwsnort: DNE wily_fwsnort: ignored (reached end-of-life) xenial_fwsnort: not-affected (1.6.4-1) yakkety_fwsnort: ignored (reached end-of-life) zesty_fwsnort: ignored (reached end-of-life) artful_fwsnort: ignored (reached end-of-life) bionic_fwsnort: not-affected (1.6.4-1) cosmic_fwsnort: not-affected (1.6.4-1) disco_fwsnort: not-affected (1.6.4-1) devel_fwsnort: not-affected (1.6.4-1)