CVE-2014-1693 Affecting erlang package, versions <1:16.b.3.1-dfsg-3


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
1.39% (87th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-ERLANG-293131
  • published8 Dec 2014
  • disclosed8 Dec 2014

Introduced: 8 Dec 2014

CVE-2014-1693  (opens in a new tab)

How to fix?

Upgrade Debian:unstable erlang to version 1:16.b.3.1-dfsg-3 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream erlang package and not the erlang package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inject arbitrary FTP commands via CRLF sequences in the (1) user, (2) account, (3) cd, (4) ls, (5) nlist, (6) rename, (7) delete, (8) mkdir, (9) rmdir, (10) recv, (11) recv_bin, (12) recv_chunk_start, (13) send, (14) send_bin, (15) send_chunk_start, (16) append_chunk_start, (17) append, or (18) append_bin command.

CVSS Scores

version 3.1