Skip to content

Commit 0b0c7c8

Browse files
jasnowpostmodern
andauthored
Updated CVE-2014-10075 advisory to current standards; Removed/replaced dead links (#895)
--------- Co-authored-by: Postmodern <[email protected]>
1 parent df050ed commit 0b0c7c8

File tree

1 file changed

+7
-8
lines changed

1 file changed

+7
-8
lines changed

gems/karo/CVE-2014-10075.yml

Lines changed: 7 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,9 @@
11
---
22
gem: karo
3-
library: rubygems
4-
framework: rubygems
5-
platform: rubygems
63
cve: 2014-10075
74
osvdb: 108573
85
ghsa: qfwq-chf4-jvwg
9-
url: https://nvd.nist.gov/vuln/detail/CVE-2014-10075
6+
url: https://github.com/advisories/GHSA-qfwq-chf4-jvwg
107
title: karo Gem for Ruby db.rb Metacharacter Handling Remote Command Execution
118
date: 2014-06-30
129
description: |
@@ -21,13 +18,15 @@ description: |
2118
in a Command ('Command Injection')
2219
2320
* Severity: CRITICAL - CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
21+
cvss_v2: 7.5
2422
cvss_v3: 9.8
23+
notes: "Never patched"
2524
related:
2625
url:
2726
- https://nvd.nist.gov/vuln/detail/CVE-2014-10075
28-
- http://www.vapid.dhs.org/advisories/karo-2.3.8.html
29-
- http://www.vapidlabs.com/advisory.php?v=63
30-
- http://osvdb.org/show/osvdb/108573
31-
- https://github.com/advisories/GHSA-qf67-vmxx-gp4jGHSA-qfwq-chf4-jvwg.json
3227
- https://github.com/rahult/karo
3328
- https://github.com/rahult/karo/blob/master/CHANGELOG.md
29+
- https://web.archive.org/web/20250421021935/http://www.vapid.dhs.org/advisories/karo-2.3.8.html
30+
- http://www.vapidlabs.com/advisory.php?v=63
31+
- https://www.openwall.com/lists/oss-security/2014/07/07/22
32+
- https://github.com/advisories/GHSA-qfwq-chf4-jvwg

0 commit comments

Comments
 (0)