Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-2588

Published: March 25, 2025Last modified: June 7, 2025

Description

A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulation of the argument re leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

Severity score breakdown

ParameterValue
Base score3.3
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Notes

CVE says 1.14.1, but Debian marks 1.12.0-2 as vulnerable. Needs investigation. Fix: https://github.com/hercules-team/augeas/commit/af2aa88ab37fc48167d8c5e43b1770a4ba2ff403

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSaugeasUnknown (1.12.0-r0)
StreamaugeasUnknown (1.12.0-r0)

References

ON THIS PAGE