UBUNTU-CVE-2014-5339

Source
https://ubuntu.com/security/CVE-2014-5339
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-5339.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-5339
Upstream
  • CVE-2014-5339
Withdrawn
2025-07-18T16:43:04Z
Published
2014-09-02T14:55:00Z
Modified
2025-07-16T07:32:07.415197Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

CheckMK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write checkmk config files (.mk files) to arbitrary locations via vectors related to row selections.

References

Affected packages

Ubuntu:16.04:LTS / check-mk

Package

Name
check-mk
Purl
pkg:deb/ubuntu/check-mk@1.2.6p12-1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.6p12-1

Affected versions

1.*
1.2.6p5-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "check-mk-agent",
            "binary_version": "1.2.6p12-1"
        },
        {
            "binary_name": "check-mk-agent-logwatch",
            "binary_version": "1.2.6p12-1"
        },
        {
            "binary_name": "check-mk-config-icinga",
            "binary_version": "1.2.6p12-1"
        },
        {
            "binary_name": "check-mk-config-nagios3",
            "binary_version": "1.2.6p12-1"
        },
        {
            "binary_name": "check-mk-doc",
            "binary_version": "1.2.6p12-1"
        },
        {
            "binary_name": "check-mk-livestatus",
            "binary_version": "1.2.6p12-1"
        },
        {
            "binary_name": "check-mk-livestatus-dbgsym",
            "binary_version": "1.2.6p12-1"
        },
        {
            "binary_name": "check-mk-multisite",
            "binary_version": "1.2.6p12-1"
        },
        {
            "binary_name": "check-mk-server",
            "binary_version": "1.2.6p12-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-5339.json"