CVE-2014-6394
Publication date 8 October 2014
Last updated 24 July 2024
Ubuntu priority
visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using “public-restricted” under a “public” directory.
Status
Package | Ubuntu Release | Status |
---|---|---|
node-send | ||
18.04 LTS bionic |
Fixed 0.9.4-1
|
|
16.04 LTS xenial |
Fixed 0.9.4-1
|
|
14.04 LTS trusty | Not in release | |