Vulnerability Description
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in their username or password.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Echor Project | Echor | 0.1.6 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2014/01/31/10Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/01/31/10Mailing ListThird Party Advisory
FAQ
What is CVE-2014-1834?
CVE-2014-1834 is a vulnerability with a CVSS score of 7.8 (HIGH). The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in their username or password.
How severe is CVE-2014-1834?
CVE-2014-1834 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-1834?
Check the references section above for vendor advisories and patch information. Affected products include: Echor Project Echor.