CVE-2014-6311: Critical severity Vanderbilt Adaptive Communication Environment vulnerability
Published Sep 7, 2014
·Updated
generatedoygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.
Affected Software
7 affected componentsFixes available
Vanderbilt Adaptive Communication Environment<=6.2.6
Vanderbilt Adaptive Communication Environment=6.2.7
Vanderbilt Adaptive Communication Environment=6.2.7-dfsg-2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/ace
6.5.12+dfsg-37.0.8+dfsg-28.0.2+dfsg-28.0.5+dfsg-2
Event History
Sep 7, 2014
Data Sourced
via Debian·06:27 AM
SeverityAffected Software
Nov 22, 2019
CVE Published
via MITRE·06:22 PM
Data Sourced
via MITRE·06:22 PM
Description
Feb 18, 2026
Data Sourced
via Debian·08:02 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6311?
CVE-2014-6311 is considered a high severity vulnerability due to its potential to allow attackers to gain elevated privileges.
2
How do I fix CVE-2014-6311?
To fix CVE-2014-6311, upgrade to ace version 6.2.7+dfsg-2 or later.
3
What versions of ace are affected by CVE-2014-6311?
Versions of ace prior to 6.2.7, including 6.2.6 and earlier, are affected by CVE-2014-6311.
4
What is the main issue with CVE-2014-6311?
CVE-2014-6311 allows for predictable file names to be created in the /tmp directory, potentially leading to privilege escalation.
5
Which operating systems are affected by CVE-2014-6311?
CVE-2014-6311 affects several versions of Debian GNU/Linux.