A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulation of the argument re leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
CVSS Details
- CVSS 4.0 Base Score: 4.8 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution existsUpgrade augeas | May 15, 2025 | Mar 21, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade augeas | Jul 11, 2025 | Mar 21, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade augeas | Aug 13, 2025 | Jun 30, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade augeas.rpmUpgrade augeas | Jul 21, 2025 | Mar 21, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade augeas | Jul 1, 2025 | Mar 21, 2025 |
| Suse | — | Upgrade augeasUpgrade augeas-lense-testsUpgrade augeas-lensesUpgrade augeas-develUpgrade libfa1-32bitUpgrade augeas-devel-32bitUpgrade libaugeas0-32bitUpgrade augeas-bash-completionUpgrade libfa1Upgrade libaugeas0 | May 13, 2025 | Mar 21, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub