{"id":"CVE-2020-14976","details":"GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration file while executing in a setuid root context.","modified":"2026-07-08T19:45:46.521423Z","published":"2020-06-23T20:15:12.927Z","references":[{"type":"ADVISORY","url":"https://github.com/GNS3/gns3-server/releases/tag/v2.1.17"},{"type":"ADVISORY","url":"https://www.gns3.com/"},{"type":"FIX","url":"https://github.com/GNS3/ubridge/commit/2eb0d1dab6a6de76cf3556130a2d52af101077db"},{"type":"EVIDENCE","url":"https://theevilbit.github.io/posts/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gns3/gns3-server","events":[{"introduced":"0"},{"fixed":"6b54cc27dafedaecaf925f1e131d84c1e37f13fb"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v2.1.16","v2.1.15","v2.1.14","v2.1.13","v2.1.12","v2.1.11","v2.1.10","v2.1.7","v2.1.6","v2.1.5","v2.1.4","v2.1.3","v2.1.2","v2.1.0","v2.1.0rc4","v2.1.0rc3","v2.1.0rc2","v2.1.0b2","v2.1.0b1","v2.1.0a2","v2.1.0a1","v2.0.0b3","v2.0.0b2","v2.0.0b1","v2.0.0a4","v2.0.0a3","v2.0.0a2","v2.0.0a1","v1.4.0rc2","v1.4.0rc1","v1.4.0b5","v1.4.0b4","v1.4.0b3","v1.4.0beta2","v1.4.0beta1","v1.4.0alpha4","v1.4.0alpha3","v1.4.0alpha1","v1.3.1","v1.3.1rc4","v1.3.0","v1.3.0rc2","v1.2.3","v1.3.0rc1","v1.2.2","v1.2.1","v1.2","v1.1","v1.0","v1.0-beta4","v1.0-beta3","v1.0-beta2","v1.0-beta1","v1.0-alpha8","v1.0-alpha7","v1.0-alpha6","v1.0-alpha5","v1.0-alpha4","v1.0-alpha3","1.0-alpha2","v1.0-alpha1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-14976.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/gns3/ubridge","events":[{"introduced":"0"},{"last_affected":"95cdb49cec4237d6349cf38b2b3d5e58d4ff465d"},{"fixed":"2eb0d1dab6a6de76cf3556130a2d52af101077db"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:gns3:ubridge:*:*:*:*:*:macos:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.9.18"}]}}],"versions":["v0.9.18","v0.9.17","v0.9.16","v0.9.15","v0.9.14","v0.9.13","v0.9.11","v0.9.10","v0.9.7","v0.9.6","v0.9.5","v0.9.4","v0.9.3","v0.9.2","v0.9.1","v0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-14976.json","vanir_signatures_modified":"2026-07-08T19:45:46Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["265850367731470298941602382151312060980","289674360931346378101879824949876529007","106477639094438218222040658658249172996","172699477009183577936036454660150799316","281372692244940741176643152889247552765","91616182508746529756050155610897265965","309148639836150701363525286184763198188","148347349425304758232367714523919767514","134224082854366621195085853342399150645","171720720016666648477290419182473583382","160509415694025110407423957687781611724"],"threshold":0.9},"id":"CVE-2020-14976-3b67f32d","signature_type":"Line","signature_version":"v1","source":"https://github.com/gns3/ubridge/commit/2eb0d1dab6a6de76cf3556130a2d52af101077db","target":{"file":"src/iniparser/iniparser.c"}},{"signature_version":"v1","source":"https://github.com/gns3/ubridge/commit/2eb0d1dab6a6de76cf3556130a2d52af101077db","target":{"file":"src/parse.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["64865900387092539737807046522785556551","140524880231888173587844582122141946266","249917321025574017722877724538433949832","88045354632534678241792192394035187424"]},"id":"CVE-2020-14976-75dca24f","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["307679288734870480734655321220263235758","173124878271179979875813809784544906513","285052786989348092953683193161552711385","164630037979637347732873737821428320892","51297103856361491509793688593429624879","7339475708965471308788513831960141370","259197655807510667277793536591231692273"],"threshold":0.9},"id":"CVE-2020-14976-99d677ec","signature_type":"Line","signature_version":"v1","source":"https://github.com/gns3/ubridge/commit/2eb0d1dab6a6de76cf3556130a2d52af101077db","target":{"file":"src/iniparser/iniparser.h"}},{"deprecated":false,"digest":{"function_hash":"158274898388520807559066150982828201302","length":2056},"id":"CVE-2020-14976-ae02b975","signature_type":"Function","signature_version":"v1","source":"https://github.com/gns3/ubridge/commit/2eb0d1dab6a6de76cf3556130a2d52af101077db","target":{"file":"src/parse.c","function":"parse_config"}},{"source":"https://github.com/gns3/ubridge/commit/2eb0d1dab6a6de76cf3556130a2d52af101077db","target":{"file":"src/iniparser/iniparser.c","function":"iniparser_load"},"deprecated":false,"digest":{"function_hash":"138374734529294390996538475399857771297","length":1870},"id":"CVE-2020-14976-d99ab4df","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}