CVE-2014-0479

medium
Published 2014-08-06 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

reportbug before 6.4.4+deb7u1 and 6.5.x before 6.5.0+nmu1 allows remote attackers to execute arbitrary commands via vectors related to compare_versions and reportbug/checkversions.py.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-0479

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed6.5.0+nmu1
debian debianbullseyefixed6.5.0+nmu1
debian debianforkyfixed6.5.0+nmu1
debian debiansidfixed6.5.0+nmu1
debian debiantrixiefixed6.5.0+nmu1

Application impact

VendorProductVersionsFixed
ubuntu canonicalreportbug{"endIncluding":"6.5.0"}
debian debianreportbug{"endIncluding":"6.4.4"}

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.