A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulation of the argument re leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 05 Jul 2025 15:00:00 +0000

Type Values Removed Values Added
References

Wed, 28 May 2025 17:15:00 +0000

Type Values Removed Values Added
References

Thu, 22 May 2025 03:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Tue, 01 Apr 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Augeas
Augeas augeas
CPEs cpe:2.3:a:augeas:augeas:1.14.1:*:*:*:*:*:*:*
Vendors & Products Augeas
Augeas augeas

Fri, 21 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Mar 2025 12:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulation of the argument re leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Title Hercules Augeas fa.c re_case_expand null pointer dereference
Weaknesses CWE-404
CWE-476
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-03-21T17:24:55.111Z

Reserved: 2025-03-21T06:32:24.166Z

Link: CVE-2025-2588

cve-icon Vulnrichment

Updated: 2025-03-21T17:24:50.997Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-21T12:15:26.553

Modified: 2025-04-01T20:24:28.240

Link: CVE-2025-2588

cve-icon Redhat

Severity : Low

Publid Date: 2025-03-21T12:00:10Z

Links: CVE-2025-2588 - Bugzilla

cve-icon OpenCVE Enrichment

No data.