Candidate: CVE-2014-1845 PublicDate: 2018-04-27 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1845 https://git.enlightenment.org/core/enlightenment.git/commit/?id=ea605237bb64ee09341121461b3d2c0f5dbe832d https://git.enlightenment.org/core/enlightenment.git/commit/?id=126afd0fda493deec8398088e6e928b4d2e5f463 https://git.enlightenment.org/core/enlightenment.git/commit/?id=8cabf2708520539cf25ca0a876f9c044f6d56a77 Description: An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging failure to properly sanitize the environment. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737705 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_e17: upstream_e17: needs-triage lucid_e17: DNE precise_e17: ignored (reached end-of-life) precise/esm_e17: DNE (precise was needed) quantal_e17: ignored (reached end-of-life) saucy_e17: ignored (reached end-of-life) trusty_e17: not-affected (0.17.3-3) trusty/esm_e17: DNE (trusty was not-affected [0.17.3-3]) utopic_e17: not-affected (0.17.3-3) vivid_e17: not-affected (0.17.3-3) vivid/stable-phone-overlay_e17: DNE vivid/ubuntu-core_e17: DNE wily_e17: not-affected (0.17.3-3) xenial_e17: not-affected (0.17.3-3) yakkety_e17: not-affected (0.17.3-3) zesty_e17: not-affected (0.17.3-3) devel_e17: not-affected (0.17.3-3)