Vulnerabilities > CVE-2014-7204 - Resource Management Errors vulnerability in multiple products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 | |
OS | 1 | |
OS | 2 | |
Application | 1 |
Common Weakness Enumeration (CWE)
Nessus
NASL family Mandriva Local Security Checks NASL id MANDRIVA_MDVSA-2015-178.NASL description Updated ctags package fixes security vulnerability : A denial of service issue was discovered in ctags 5.8. A remote attacker could cause excessive CPU usage and disk space consumption via a crafted JavaScript file by triggering an infinite loop (CVE-2014-7204). last seen 2020-06-01 modified 2020-06-02 plugin id 82453 published 2015-03-31 reporter This script is Copyright (C) 2015-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/82453 title Mandriva Linux Security Advisory : ctags (MDVSA-2015:178) NASL family Debian Local Security Checks NASL id DEBIAN_DSA-3042.NASL description Stefano Zacchiroli discovered a vulnerability in exuberant-ctags, a tool to build tag file indexes of source code definitions: Certain JavaScript files cause ctags to enter an infinite loop until it runs out of disk space, resulting in denial of service. last seen 2020-03-17 modified 2014-10-06 plugin id 78044 published 2014-10-06 reporter This script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/78044 title Debian DSA-3042-1 : exuberant-ctags - security update NASL family Mandriva Local Security Checks NASL id MANDRIVA_MDVSA-2014-206.NASL description Updated ctags package fixes security vulnerability : A denial of service issue was discovered in ctags 5.8. A remote attacker could cause excessive CPU usage and disk space consumption via a crafted JavaScript file by triggering an infinite loop (CVE-2014-7204). last seen 2020-06-01 modified 2020-06-02 plugin id 78685 published 2014-10-27 reporter This script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/78685 title Mandriva Linux Security Advisory : ctags (MDVSA-2014:206) NASL family Ubuntu Local Security Checks NASL id UBUNTU_USN-2371-1.NASL description It was discovered that Exuberant Ctags incorrectly handled certain minified js files. An attacker could use this issue to possibly cause Exuberant Ctags to consume resources, resulting in a denial of service. Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 78107 published 2014-10-09 reporter Ubuntu Security Notice (C) 2014-2019 Canonical, Inc. / NASL script (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/78107 title Ubuntu 12.04 LTS / 14.04 LTS : exuberant-ctags vulnerability (USN-2371-1) NASL family Debian Local Security Checks NASL id DEBIAN_DLA-69.NASL description Stefano Zacchiroli discovered that certain JavaScript input files cause ctags to enter an infinite loop until it runs out of disk space. This update fixes the JavaScript parser. NOTE: Tenable Network Security has extracted the preceding description block directly from the DLA security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-03-17 modified 2015-03-26 plugin id 82214 published 2015-03-26 reporter This script is Copyright (C) 2015-2020 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/82214 title Debian DLA-69-1 : exuberant-ctags security update NASL family SuSE Local Security Checks NASL id SUSE_SU-2016-2097-1.NASL description This update for ctags fixes the following issues : - CVE-2014-7204: Potential denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file. (bsc#899486) - Missing Requires(post) on coreutils as it is using rm(1). (bsc#976920) Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 93297 published 2016-09-02 reporter This script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/93297 title SUSE SLED12 / SLES12 Security Update : ctags (SUSE-SU-2016:2097-1) NASL family Fedora Local Security Checks NASL id FEDORA_2014-11924.NASL description A denial of service issue was discovered in ctags. This could lead to excessive CPU and disk space consumption. This update resolves this issue Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-03-17 modified 2014-10-11 plugin id 78248 published 2014-10-11 reporter This script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/78248 title Fedora 20 : ctags-5.8-16.fc20 (2014-11924)
References
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742605
- http://sourceforge.net/p/ctags/code/791/
- http://www.debian.org/security/2014/dsa-3042
- http://www.openwall.com/lists/oss-security/2014/09/29/40
- http://www.ubuntu.com/usn/USN-2371-1
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:178
- http://advisories.mageia.org/MGASA-2014-0415.html