{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Low"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "local code execution via string expansion",
    "tracking": {
      "current_release_date": "2026-08-11T14:03:58+00:00",
      "generator": {
        "date": "2026-08-11T14:03:58+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2014-2972",
      "initial_release_date": "2014-07-23T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:03:58+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 5.11",
            "product": {
              "name": "Red Hat Enterprise Linux 5.11",
              "product_id": "rhel-5.11.z.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:5"
              }
            }
          },
          {
            "category": "product_version",
            "name": "exim",
            "product": {
              "name": "exim",
              "product_id": "exim.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/exim?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exim.src as a component of Red Hat Enterprise Linux 5.11",
          "product_id": "rhel-5.11.z.els:exim.src"
        },
        "product_reference": "exim.src",
        "relates_to_product_reference": "rhel-5.11.z.els"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2014-2972",
      "cwe": {
        "id": "CWE-138",
        "name": "Improper Neutralization of Special Elements"
      },
      "discovery_date": "2014-07-23T00:00:00+00:00",
      "notes": [
        {
          "category": "other",
          "text": "Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "rhel-5.11.z.els:exim.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2014-2972"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-2972"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2014-2972"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "rhel-5.11.z.els:exim.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "version": "2.0",
            "vectorString": "AV:L/AC:H/Au:N/C:P/I:P/A:P",
            "baseScore": 3.7
          },
          "products": [
            "rhel-5.11.z.els:exim.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low",
          "product_ids": [
            "rhel-5.11.z.els:exim.src"
          ]
        }
      ],
      "title": "local code execution via string expansion"
    }
  ]
}