CVE-2014-7817
EPSS 0.16%Published: 11/24/2014Modified: 4/28/2026
Also known as:DEBIAN-CVE-2014-7817
Description
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
Affected packages (1)
- Debian/glibcfrom 0, < 2.19-14