CVE detail
CVE-2014-2524 — CVE-2014-2524
Published 2014-08-20 · Modified 2026-06-17 · Vendor mageia · Product mageia · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0043
EPSS probability
exploitation probability, 30d
36.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References