CVE-2020-14976

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-14976
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-14976.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-14976
Published
2020-06-23T20:15:12Z
Modified
2025-07-01T11:05:33.802545Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration file while executing in a setuid root context.

References

Affected packages

Git / github.com/gns3/gns3-server

Affected ranges

Type
GIT
Repo
https://github.com/gns3/gns3-server
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/gns3/ubridge
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0-alpha2

v0.*

v0.9.0
v0.9.1
v0.9.10
v0.9.11
v0.9.12
v0.9.13
v0.9.14
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9

v1.*

v1.0
v1.0-alpha1
v1.0-alpha3
v1.0-alpha4
v1.0-alpha5
v1.0-alpha6
v1.0-alpha7
v1.0-alpha8
v1.0-beta1
v1.0-beta2
v1.0-beta3
v1.0-beta4
v1.1
v1.2
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0alpha1
v1.3.0beta1
v1.3.0beta2
v1.3.0rc1
v1.3.0rc2
v1.3.1
v1.3.10
v1.3.11
v1.3.12
v1.3.13
v1.3.1rc1
v1.3.1rc2
v1.3.1rc3
v1.3.1rc4
v1.3.2
v1.3.3
v1.3.3rc1
v1.3.4
v1.3.5
v1.3.6
v1.3.7
v1.3.8
v1.3.9
v1.4.0
v1.4.0alpha1
v1.4.0alpha2
v1.4.0alpha3
v1.4.0alpha4
v1.4.0b3
v1.4.0b4
v1.4.0b5
v1.4.0beta1
v1.4.0beta2
v1.4.0rc1
v1.4.0rc2
v1.4.0rc3
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.5.0
v1.5.0a1
v1.5.0a2
v1.5.0b1
v1.5.0rc1
v1.5.0rc2
v1.5.1
v1.5.2
v1.5.3
v1.5.3.1
v1.5.3rc1
v1.5.4

v2.*

v2.0.0
v2.0.0a1
v2.0.0a2
v2.0.0a3
v2.0.0a4
v2.0.0b1
v2.0.0b2
v2.0.0b3
v2.0.0b4
v2.0.0rc1
v2.0.0rc2
v2.0.0rc3
v2.0.0rc4
v2.0.1
v2.0.2
v2.0.3
v2.1.0
v2.1.0a1
v2.1.0a2
v2.1.0b1
v2.1.0b2
v2.1.0rc1
v2.1.0rc2
v2.1.0rc3
v2.1.0rc4
v2.1.1
v2.1.10
v2.1.11
v2.1.12
v2.1.13
v2.1.14
v2.1.15
v2.1.16
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.1.7
v2.1.8
v2.1.9