CVE-2014-8517

Apple Mac OS X - Command Injection

Title source: rule

Description

The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.

Exploits (3)

metasploit WORKING POC EXCELLENT
by Jared McNeill, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/http/tnftp_savefile.rb
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteunix
https://www.exploit-db.com/exploits/43112
exploitdb WORKING POC
by dash · pythonremotebsd
https://www.exploit-db.com/exploits/35427

Scores

EPSS 0.8498
EPSS Percentile 99.3%

Classification

CWE
CWE-77
Status draft

Affected Products (25)

apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
netbsd/netbsd
netbsd/netbsd
netbsd/netbsd
netbsd/netbsd
netbsd/netbsd
netbsd/netbsd
netbsd/netbsd
netbsd/netbsd
netbsd/netbsd
netbsd/netbsd
netbsd/netbsd
... and 10 more

Timeline

Published Nov 17, 2014
Tracked Since Feb 18, 2026