8.1
CVSSv3

CVE-2014-2029

Published: 29/09/2017 Updated: 10/10/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle malicious users to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configuration information from v.percona.com.

Vulnerable Product Search on Vulmon Subscribe to Product

percona toolkit 2.1

Vendor Advisories

Debian Bug report logs - #740846 percona-toolkit: CVE-2014-2029 Package: percona-toolkit; Maintainer for percona-toolkit is Dario Minnucci <midget@debianorg>; Source for percona-toolkit is src:percona-toolkit (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 5 Mar 2014 14:36:08 UTC ...