CVE-2014-0475: Path Traversal
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC, (2) LANG, or other locale environment variable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0475?
CVE-2014-0475 has a medium severity rating due to its potential to allow context-dependent attackers to bypass security restrictions.
How do I fix CVE-2014-0475?
To fix CVE-2014-0475, upgrade the GNU C Library to version 2.20 or later.
What software is affected by CVE-2014-0475?
CVE-2014-0475 affects multiple versions of the GNU C Library (glibc) prior to 2.20.
What attack vector is used in CVE-2014-0475?
CVE-2014-0475 can be exploited via directory traversal using specific locale environment variables.
Are there any known exploits for CVE-2014-0475?
While exploitation details may vary, CVE-2014-0475 exposes systems to potential abuse of the ForceCommand feature.