CVE-2014-4910: Path Traversal
Published Jul 24, 2014
·Updated
Directory traversal vulnerability in tools/backlighthelper.c in X.Org xf86-video-intel 2.99.911 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the interface name.
Affected Software
1 affected component
X xf86-video-intel=2.99.911
Event History
Jul 24, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4910?
The severity of CVE-2014-4910 is classified as medium due to the potential for arbitrary file creation or overwrite.
2
How do I fix CVE-2014-4910?
To fix CVE-2014-4910, update to a later version of the xf86-video-intel package that has addressed this vulnerability.
3
What causes CVE-2014-4910?
CVE-2014-4910 is caused by a directory traversal vulnerability in tools/backlight_helper.c allowing attackers to manipulate interface names.
4
Who is affected by CVE-2014-4910?
CVE-2014-4910 affects users of X.Org xf86-video-intel version 2.99.911.
5
Can CVE-2014-4910 be exploited remotely?
Yes, CVE-2014-4910 can be exploited remotely, allowing attackers to create or overwrite arbitrary files.