MEDIUM · 6.4

CVE-2014-1424

apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."

Vulnerability Description

apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
UbuntuApparmor<= 2.8.94-0ubuntu1.4
CanonicalUbuntu14.04

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-1424?

CVE-2014-1424 is a vulnerability with a CVSS score of 6.4 (MEDIUM). apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."

How severe is CVE-2014-1424?

CVE-2014-1424 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-1424?

Check the references section above for vendor advisories and patch information. Affected products include: Ubuntu Apparmor, Canonical Ubuntu.