Vulnerabilities > Augeas > Augeas > 1.1.0

DATE CVE VULNERABILITY TITLE RISK
2017-08-17 CVE-2017-7555 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Augeas
Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings.
network
low complexity
augeas CWE-119
7.5
2014-01-23 CVE-2013-6412 Permissions, Privileges, and Access Controls vulnerability in Augeas 1.0.0/1.1.0
The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.
local
low complexity
augeas CWE-264
4.6