CVE-2014-6262: High severity zenoss vulnerability
Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted third argument to the rrdtool.graph function, aka ZEN-15415, a related issue to CVE-2013-2131.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6262?
CVE-2014-6262 is considered a critical vulnerability due to its potential to allow remote code execution or application crashes.
How do I fix CVE-2014-6262?
To fix CVE-2014-6262, upgrade to Zenoss Core version 4.2.5 or later, or ensure that RRDtool is updated to a secure version.
What software is affected by CVE-2014-6262?
CVE-2014-6262 affects Zenoss Core versions before 4.2.5 and Debian Linux 8.0 when using the affected RRDtool module.
What attacks can be performed using CVE-2014-6262?
Attackers can execute arbitrary code or cause a denial of service by exploiting the format string vulnerabilities in the rrdtool.graph function.
Is there a workaround for CVE-2014-6262 if I cannot upgrade?
Currently, there are no known effective workarounds, so upgrading to a non-vulnerable version is strongly recommended.