DEBIAN-CVE-2014-6394

Source
https://security-tracker.debian.org/tracker/CVE-2014-6394
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2014-6394.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2014-6394
Upstream
Published
2014-10-08T17:55:05.123Z
Modified
2025-11-19T01:19:09.420516Z
Summary
[none]
Details

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.

References

Affected packages

Debian:11 / node-send

Package

Name
node-send
Purl
pkg:deb/debian/node-send?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2014-6394.json"

Debian:12 / node-send

Package

Name
node-send
Purl
pkg:deb/debian/node-send?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2014-6394.json"

Debian:13 / node-send

Package

Name
node-send
Purl
pkg:deb/debian/node-send?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2014-6394.json"

Debian:14 / node-send

Package

Name
node-send
Purl
pkg:deb/debian/node-send?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2014-6394.json"