{"id":"CVE-2014-2029","details":"The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configuration information from v.percona.com.","modified":"2026-04-10T03:43:38.637109Z","published":"2017-09-29T01:34:47Z","related":["openSUSE-SU-2024:10095-1","openSUSE-SU-2024:10120-1"],"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2014/02/19/14"},{"type":"ADVISORY","url":"https://bugs.launchpad.net/percona-toolkit/+bug/1279502"},{"type":"ADVISORY","url":"https://bugzilla.novell.com/show_bug.cgi?id=864194"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2014/02/19/14"},{"type":"FIX","url":"https://bugzilla.novell.com/show_bug.cgi?id=864194"},{"type":"REPORT","url":"https://bugs.launchpad.net/percona-toolkit/+bug/1279502"},{"type":"REPORT","url":"https://bugzilla.novell.com/show_bug.cgi?id=864194"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}