CVE-2014-1921

parcimonie before 0.8.1, when using a large keyring, sleeps for the same amount of time between fetches, which allows attackers to correlate key fetches via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:parcimonie_project:parcimonie:*:*:*:*:*:*:*:*
cpe:2.3:a:parcimonie_project:parcimonie:0.6-1:*:*:*:*:*:*:*
cpe:2.3:a:parcimonie_project:parcimonie:0.6-3:*:*:*:*:*:*:*
cpe:2.3:a:parcimonie_project:parcimonie:0.7-1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-02-14 15:55

Updated : 2024-02-28 12:20


NVD link : CVE-2014-1921

Mitre link : CVE-2014-1921

CVE.ORG link : CVE-2014-1921


JSON object : View

Products Affected

parcimonie_project

  • parcimonie
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')