Medium severity5.5NVD Advisory· Published Jan 10, 2018· Updated Jun 17, 2026
CVE-2014-4994
CVE-2014-4994
Description
lib/gyazo/client.rb in the gyazo gem 1.0.0 for Ruby allows local users to write to arbitrary files via a symlink attack on a temporary file, related to time-based filenames.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
gyazoRubyGems | >= 1.0.0, < 2.0.0 | 2.0.0 |
Affected products
2- cpe:2.3:a:gyazo_project:gyazo:1.0.0:*:*:*:*:ruby:*:*
Patches
Vulnerability mechanics
References
7- www.vapid.dhs.org/advisories/gyazo-1.0.0.htmlnvdExploitThird Party Advisory
- www.openwall.com/lists/oss-security/2014/07/07/13nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2014/07/17/5nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-6x45-86q6-rcmrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-4994ghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/gyazo/CVE-2014-4994.ymlghsaWEB
- web.archive.org/web/20200229061943/http://www.vapid.dhs.org/advisories/gyazo-1.0.0.htmlghsaWEB
News mentions
0No linked articles in our index yet.