First published: Thu Nov 27 2014(Updated: )
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE | =13.1 | |
openSUSE | =13.2 | |
Fedoraproject Fedora | =20 | |
Fedoraproject Fedora | =21 | |
kernel util-linux | <=2.24.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9114 has a high severity rating due to the potential for arbitrary code execution with root privileges.
To fix CVE-2014-9114, update to the latest version of the util-linux package that addresses this vulnerability.
CVE-2014-9114 affects util-linux versions prior to 2.26rc-1 on specific versions of openSUSE and Fedora.
CVE-2014-9114 is primarily a local attack vector that can be exploited when users run blkid on a malicious USB drive.
The potential consequences of CVE-2014-9114 include unauthorized execution of commands with elevated privileges, which could compromise system security.