CVE-2014-6394

NameCVE-2014-6394
Descriptionvisionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-send (PTS)jessie, stretch0.9.4-1fixed
buster0.16.2-1fixed
bullseye0.17.1-2fixed
bookworm0.18.0+~cs1.19.1-3fixed
sid, trixie1.1.0+~cs1.19.4-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-sendsource(unstable)0.9.4-1

Notes

https://nodesecurity.io/advisories/send-directory-traversal

Search for package or bug name: Reporting problems