CVE-2014-8517

high
Published 2014-11-17 · Modified 2026-05-06
CVSS v3
CVSS v2
7.5
VIR risk
8.5

Description

The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.

Predictions

Exploit likelihood
55%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-8517

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-013.txt.asc

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2014-8517.html

Exploits

Exploit-DB

OS impact

OSVersionStatusFixed in
suse slesaffected
macos macos10.8.5affected
macos macos10.9.5affected
macos macos10.10.0affected
macos macos10.10.1affected
freebsd freebsd5.1affected
freebsd freebsd5.1.1affected
freebsd freebsd5.1.2affected
freebsd freebsd5.1.3affected
freebsd freebsd5.1.4affected
freebsd freebsd5.2affected
freebsd freebsd5.2.1affected
freebsd freebsd5.2.2affected
freebsd freebsd6.0affected
freebsd freebsd6.0.1affected
freebsd freebsd6.0.2affected
freebsd freebsd6.0.3affected
freebsd freebsd6.0.4affected
freebsd freebsd6.0.5affected
freebsd freebsd6.0.6affected
freebsd freebsd6.1affected
freebsd freebsd6.1.1affected
freebsd freebsd6.1.2affected
freebsd freebsd6.1.3affected
freebsd freebsd6.1.4affected
freebsd freebsd6.1.5affected
debian debianbookwormfixed20130505-2
debian debianbullseyefixed20130505-2
debian debianforkyfixed20130505-2
debian debiansidfixed20130505-2
debian debiantrixiefixed20130505-2

References

CWEs

CWE-77

Verify integrity in audit chain (admin only). AS-IS.