CVE-2014-9471
Publication date 31 December 2014
Last updated 24 July 2024
Ubuntu priority
The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.
Status
Package | Ubuntu Release | Status |
---|---|---|
coreutils | ||
14.04 LTS trusty |
Fixed 8.21-1ubuntu5.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2473-1
- coreutils vulnerabilities
- 14 January 2015