UBUNTU-CVE-2014-6311

Source
https://ubuntu.com/security/CVE-2014-6311
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-6311.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-6311
Upstream
Published
2019-11-22T19:15:00Z
Modified
2026-05-20T16:03:09.440541483Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.

References

Affected packages

Ubuntu:16.04:LTS
ace

Package

Name
ace
Purl
pkg:deb/ubuntu/ace?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.2.8+dfsg-1
6.3.3+dfsg-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "ace-gperf",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "ace-netsvcs",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "gperf-ace",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-flreactor-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-foxreactor-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-htbp-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-inet-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-inet-ssl-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-qtreactor-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-rmcast-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-ssl-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-tkreactor-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-tmcast-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-xml-utils-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libace-xtreactor-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libacexml-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libkokyu-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "libnetsvcs-6.3.3",
            "binary_version": "6.3.3+dfsg-1"
        },
        {
            "binary_name": "mpc-ace",
            "binary_version": "6.3.3+dfsg-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-6311.json"
Ubuntu:18.04:LTS
ace

Package

Name
ace
Purl
pkg:deb/ubuntu/ace?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.4.5+dfsg-1
6.4.5+dfsg-1build1
6.4.5+dfsg-1build2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "ace-gperf",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "ace-netsvcs",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "gperf-ace",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libace-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libace-flreactor-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libace-foxreactor-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libace-htbp-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libace-inet-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libace-inet-ssl-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libace-rmcast-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libace-ssl-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libace-tkreactor-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libace-tmcast-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libace-xml-utils-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libace-xtreactor-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libacexml-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libkokyu-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "libnetsvcs-6.4.5",
            "binary_version": "6.4.5+dfsg-1build2"
        },
        {
            "binary_name": "mpc-ace",
            "binary_version": "6.4.5+dfsg-1build2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-6311.json"
Ubuntu:20.04:LTS
ace

Package

Name
ace
Purl
pkg:deb/ubuntu/ace?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.4.5+dfsg-1build2
6.4.5+dfsg-1build3.1
6.4.5+dfsg-1build4

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "ace-gperf",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "ace-netsvcs",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "gperf-ace",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libace-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libace-flreactor-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libace-foxreactor-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libace-htbp-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libace-inet-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libace-inet-ssl-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libace-rmcast-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libace-ssl-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libace-tkreactor-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libace-tmcast-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libace-xml-utils-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libace-xtreactor-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libacexml-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libkokyu-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "libnetsvcs-6.4.5",
            "binary_version": "6.4.5+dfsg-1build4"
        },
        {
            "binary_name": "mpc-ace",
            "binary_version": "6.4.5+dfsg-1build4"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-6311.json"
Ubuntu:22.04:LTS
ace

Package

Name
ace
Purl
pkg:deb/ubuntu/ace?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.5.12+dfsg-3
7.*
7.0.3+dfsg-2
7.0.3+dfsg-2build1
7.0.6+dfsg-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "ace-gperf",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "ace-netsvcs",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libace-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libace-flreactor-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libace-foxreactor-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libace-htbp-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libace-inet-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libace-inet-ssl-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libace-rmcast-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libace-ssl-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libace-tkreactor-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libace-tmcast-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libace-xml-utils-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libace-xtreactor-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libacexml-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libkokyu-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "libnetsvcs-7.0.6",
            "binary_version": "7.0.6+dfsg-2"
        },
        {
            "binary_name": "mpc-ace",
            "binary_version": "7.0.6+dfsg-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-6311.json"
Ubuntu:24.04:LTS
ace

Package

Name
ace
Purl
pkg:deb/ubuntu/ace?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.0.8+dfsg-2
7.1.2+dfsg-2
7.1.2+dfsg-2.1
7.1.2+dfsg-2.1build1
7.1.2+dfsg-2.1build2
7.1.2+dfsg-2.1ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "ace-gperf",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "ace-netsvcs",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libace-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libace-flreactor-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libace-foxreactor-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libace-htbp-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libace-inet-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libace-inet-ssl-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libace-rmcast-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libace-ssl-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libace-tkreactor-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libace-tmcast-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libace-xml-utils-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libace-xtreactor-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libacexml-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libkokyu-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "libnetsvcs-7.1.2t64",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        },
        {
            "binary_name": "mpc-ace",
            "binary_version": "7.1.2+dfsg-2.1ubuntu0.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-6311.json"
Ubuntu:25.10
ace

Package

Name
ace
Purl
pkg:deb/ubuntu/ace?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*
8.0.2+dfsg-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "ace-gperf",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "ace-netsvcs",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libace-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libace-flreactor-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libace-foxreactor-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libace-htbp-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libace-inet-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libace-inet-ssl-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libace-rmcast-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libace-ssl-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libace-tkreactor-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libace-tmcast-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libace-xml-utils-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libace-xtreactor-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libacexml-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libkokyu-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "libnetsvcs-8.0.2",
            "binary_version": "8.0.2+dfsg-2"
        },
        {
            "binary_name": "mpc-ace",
            "binary_version": "8.0.2+dfsg-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-6311.json"
Ubuntu:26.04:LTS
ace

Package

Name
ace
Purl
pkg:deb/ubuntu/ace?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*
8.0.2+dfsg-2
8.0.4+dfsg-2
8.0.5+dfsg-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "ace-gperf",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "ace-netsvcs",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libace-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libace-flreactor-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libace-foxreactor-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libace-htbp-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libace-inet-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libace-inet-ssl-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libace-rmcast-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libace-ssl-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libace-tkreactor-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libace-tmcast-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libace-xml-utils-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libace-xtreactor-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libacexml-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libkokyu-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "libnetsvcs-8.0.5",
            "binary_version": "8.0.5+dfsg-2"
        },
        {
            "binary_name": "mpc-ace",
            "binary_version": "8.0.5+dfsg-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-6311.json"