PT-2020-7723 · Rrdtool+1 · Rrdtool+1
Published
2020-02-12
·
Updated
2022-01-01
·
CVE-2014-6262
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
RRDtool versions prior to 4.2.5
Zenoss Core versions prior to 4.2.5
Description
The issue is related to multiple format string vulnerabilities in the python module of RRDtool. These vulnerabilities can be exploited by remote attackers to execute arbitrary code or cause a denial of service, resulting in an application crash. The exploitation occurs through a crafted third argument to the
rrdtool.graph function.Recommendations
For RRDtool versions prior to 4.2.5, update to version 4.2.5 or later to resolve the issue.
For Zenoss Core versions prior to 4.2.5, update to version 4.2.5 or later to resolve the issue.
Fix
DoS
RCE
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rrdtool
Zenoss Core