CVE-2014-6262

HIGH

Zenoss Core < 4.2.5 - Remote Code Execution via RRDtool Python Module Format String

Title source: manual
STIX 2.1

Description

Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted third argument to the rrdtool.graph function, aka ZEN-15415, a related issue to CVE-2013-2131.

References (8)

Core 8
Core References
Third Party Advisory, US Government Resource x_refsource_misc
http://www.kb.cert.org/vuls/id/449452
Third Party Advisory, VDB Entry x_refsource_misc
https://www.securityfocus.com/bid/71540
Third Party Advisory x_refsource_misc
https://github.com/oetiker/rrdtool-1.x/pull/532
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/03/msg00000.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/03/msg00003.html

Scores

CVSS v3 7.5
EPSS 0.0707
EPSS Percentile 93.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-134
Status published
Products (2)
debian/debian_linux 8.0
zenoss/zenoss_core < 4.2.5
Published Feb 12, 2020
Tracked Since Feb 18, 2026