CVE-2014-1921

parcimonie before 0.8.1, when using a large keyring, sleeps for the same amount of time between fetches, which allows attackers to correlate key fetches via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:parcimonie_project:parcimonie:*:*:*:*:*:*:*:*
cpe:2.3:a:parcimonie_project:parcimonie:0.6-1:*:*:*:*:*:*:*
cpe:2.3:a:parcimonie_project:parcimonie:0.6-3:*:*:*:*:*:*:*
cpe:2.3:a:parcimonie_project:parcimonie:0.7-1:*:*:*:*:*:*:*

History

21 Nov 2024, 02:05

Type Values Removed Values Added
References () http://seclists.org/oss-sec/2014/q1/305 - () http://seclists.org/oss-sec/2014/q1/305 -
References () http://seclists.org/oss-sec/2014/q1/308 - () http://seclists.org/oss-sec/2014/q1/308 -
References () http://www.debian.org/security/2014/dsa-2860 - () http://www.debian.org/security/2014/dsa-2860 -
References () http://www.securityfocus.com/bid/65505 - () http://www.securityfocus.com/bid/65505 -
References () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=738134 - () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=738134 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/91118 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/91118 -
References () https://gaffer.ptitcanardnoir.org/intrigeri/files/parcimonie/App-Parcimonie-0.8.1.tar.gz - Patch () https://gaffer.ptitcanardnoir.org/intrigeri/files/parcimonie/App-Parcimonie-0.8.1.tar.gz - Patch

Information

Published : 2014-02-14 15:55

Updated : 2024-11-21 02:05


NVD link : CVE-2014-1921

Mitre link : CVE-2014-1921

CVE.ORG link : CVE-2014-1921


JSON object : View

Products Affected

parcimonie_project

  • parcimonie
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')