CVE-2014-6262

NameCVE-2014-6262
DescriptionMultiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted third argument to the rrdtool.graph function, aka ZEN-15415, a related issue to CVE-2013-2131.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2131-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rrdtool (PTS)jessie, jessie (lts)1.4.8-1.2+deb8u2fixed
stretch1.6.0-1fixed
buster1.7.1-2fixed
bullseye1.7.2-3fixed
bookworm1.7.2-4fixed
sid, trixie1.7.2-4.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rrdtoolsourcewheezy(unfixed)end-of-life
rrdtoolsourcejessie1.4.8-1.2+deb8u1DLA-2131-1
rrdtoolsource(unstable)1.5.4-1

Notes

https://github.com/oetiker/rrdtool-1.x/pull/532
https://github.com/oetiker/rrdtool-1.x/commit/64ed5314af1255ab6dded45f70b39cdeab5ae2ec (v1.5.0-rc1)
https://github.com/oetiker/rrdtool-1.x/commit/85261a013112e278c90224033f5b0592ee387786 (v1.4.9)

Search for package or bug name: Reporting problems