Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-1875

13
FAUCET Score

CVE-2014-1875 describes a local file write vulnerability in the Capture::Tiny Perl module, affecting versions prior to 0.24. An attacker can exploit this flaw through a symlink attack on a temporary file, potentially overwriting arbitrary files with the privileges of the affected process. While the CVSS score is low (3.6) due to its local attack vector and low impact on confidentiality, it allows for partial integrity and availability compromise. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it is not a widely targeted vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.23CPE matchmatch criteria
cpe:2.3:a:cspan:capture-tiny:*:*:*:*:*:*:*:*
0.20CPE matchmatch criteria
cpe:2.3:a:cspan:capture-tiny:0.20:*:*:*:*:*:*:*
0.21CPE matchmatch criteria
cpe:2.3:a:cspan:capture-tiny:0.21:*:*:*:*:*:*:*
0.22CPE matchmatch criteria
cpe:2.3:a:cspan:capture-tiny:0.22:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

3.6LOW

AV:L/AC:L/Au:N/C:N/I:P/A:P

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
4.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.52%
Probability of exploitation in next 30 days
EPSS Percentile
40.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0052 is in the 76th percentile among its peer group of 2,096 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

redhatno patchvia redhat_api
Product: Red Hat Software CollectionsFixed in: perl516-perl-Capture-Tiny

Vendor Advisories (1)

redhatCVE-2014-1875Low

perl-Capture-Tiny: insecure temporary file usage

Feb 6, 2014

References

cpansearch.perl.org / src/DAGOLDEN/Capture-Tiny-0.24/Changes
lists.fedoraproject.org / pipermail/package-announce/2014-February/128823.html
lists.fedoraproject.org / pipermail/package-announce/2014-February/128882.html
osvdb.org / 102963
bugs.debian.org / cgi-bin/bugreport.cgi
Exploit
bugzilla.redhat.com / show_bug.cgi
seclists.org / oss-sec/2014/q1/267
Exploit
seclists.org / oss-sec/2014/q1/272
secunia.com / advisories/56823
exchange.xforce.ibmcloud.com / vulnerabilities/91464
github.com / dagolden/Capture-Tiny/commit/635c9eabd52ab8042b0c841823bd6e692de87924
github.com / dagolden/Capture-Tiny/issues/16
Exploit
securityfocus.com / bid/65475