Candidate: CVE-2014-2332 PublicDate: 2015-08-31 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2332 http://packetstormsecurity.com/files/125850/DTC-A-20140324-002.txt Description: Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, related to "Insecure Direct Object References." NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2330. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742689 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_check-mk: upstream_check-mk: released (1.2.2p3-1) precise_check-mk: ignored (reached end-of-life) precise/esm_check-mk: DNE (precise was needed) trusty_check-mk: not-affected (1.2.2p3-1) trusty/esm_check-mk: DNE (trusty was not-affected [1.2.2p3-1]) vivid_check-mk: not-affected vivid/stable-phone-overlay_check-mk: DNE vivid/ubuntu-core_check-mk: DNE wily_check-mk: not-affected xenial_check-mk: not-affected yakkety_check-mk: not-affected zesty_check-mk: not-affected devel_check-mk: not-affected