VYPR
Unrated severityNVD Advisory· Published Aug 20, 2014· Updated May 6, 2026

CVE-2014-2524

CVE-2014-2524

Description

The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.

Affected products

19
  • Mageia/Mageia2 versions
    cpe:2.3:o:mageia:mageia:3.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:mageia:mageia:3.0:*:*:*:*:*:*:*
    • cpe:2.3:o:mageia:mageia:4.0:*:*:*:*:*:*:*
  • GNU/Readline14 versions
    cpe:2.3:a:gnu:readline:*:*:*:*:*:*:*:*+ 13 more
    • cpe:2.3:a:gnu:readline:*:*:*:*:*:*:*:*range: <=6.3
    • cpe:2.3:a:gnu:readline:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:readline:2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:readline:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:readline:4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:readline:4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:readline:4.2:a:*:*:*:*:*:*
    • cpe:2.3:a:gnu:readline:4.3:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:readline:5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:readline:5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:readline:5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:readline:6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:readline:6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:readline:6.2:*:*:*:*:*:*:*
  • OpenSUSE/openSUSE2 versions
    cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
    • cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.