{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "buffer overflow in mpfr_strtofr",
    "tracking": {
      "current_release_date": "2026-08-11T14:03:27+00:00",
      "generator": {
        "date": "2026-08-11T14:03:27+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2014-9474",
      "initial_release_date": "2013-12-16T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:03:27+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 6-els",
            "product": {
              "name": "Red Hat Enterprise Linux 6-els",
              "product_id": "rhel-6-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:6"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7-els",
            "product": {
              "name": "Red Hat Enterprise Linux 7-els",
              "product_id": "rhel-7-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:7"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mpfr",
            "product": {
              "name": "mpfr",
              "product_id": "mpfr",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mpfr"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mpfr",
            "product": {
              "name": "mpfr",
              "product_id": "mpfr-0:3.1.1-4.el7_9.2",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mpfr@3.1.1-4.el7_9.2?epoch=0"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mpfr",
            "product": {
              "name": "mpfr",
              "product_id": "mpfr-0:3.1.1-4.el7_9.2.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mpfr@3.1.1-4.el7_9.2?arch=src&epoch=0"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mpfr-debuginfo",
            "product": {
              "name": "mpfr-debuginfo",
              "product_id": "mpfr-debuginfo",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mpfr-debuginfo"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mpfr-devel",
            "product": {
              "name": "mpfr-devel",
              "product_id": "mpfr-devel",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mpfr-devel"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mpfr",
            "product": {
              "name": "mpfr",
              "product_id": "mpfr.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mpfr?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mpfr as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:mpfr"
        },
        "product_reference": "mpfr",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mpfr-0:3.1.1-4.el7_9.2 as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:mpfr-0:3.1.1-4.el7_9.2"
        },
        "product_reference": "mpfr-0:3.1.1-4.el7_9.2",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mpfr-0:3.1.1-4.el7_9.2.src as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:mpfr-0:3.1.1-4.el7_9.2.src"
        },
        "product_reference": "mpfr-0:3.1.1-4.el7_9.2.src",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mpfr-debuginfo as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:mpfr-debuginfo"
        },
        "product_reference": "mpfr-debuginfo",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mpfr-debuginfo as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:mpfr-debuginfo"
        },
        "product_reference": "mpfr-debuginfo",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mpfr-devel as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:mpfr-devel"
        },
        "product_reference": "mpfr-devel",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mpfr-devel as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:mpfr-devel"
        },
        "product_reference": "mpfr-devel",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mpfr.src as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:mpfr.src"
        },
        "product_reference": "mpfr.src",
        "relates_to_product_reference": "rhel-6-els.els"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2014-9474",
      "discovery_date": "2014-12-08T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhel-6-els.els:mpfr-debuginfo",
            "rhel-6-els.els:mpfr-devel",
            "rhel-7-els.els:mpfr-debuginfo",
            "rhel-7-els.els:mpfr-devel"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "Buffer overflow in the mpfr_strtofr function in GNU MPFR before 3.1.2-p11 allows context-dependent attackers to have unspecified impact via vectors related to incorrect documentation for mpn_set_str.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "rhel-7-els.els:mpfr-0:3.1.1-4.el7_9.2",
          "rhel-7-els.els:mpfr-0:3.1.1-4.el7_9.2.src"
        ],
        "known_affected": [
          "rhel-6-els.els:mpfr",
          "rhel-6-els.els:mpfr.src"
        ],
        "known_not_affected": [
          "rhel-6-els.els:mpfr-debuginfo",
          "rhel-6-els.els:mpfr-devel",
          "rhel-7-els.els:mpfr-debuginfo",
          "rhel-7-els.els:mpfr-devel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2014-9474"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-9474"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2014-9474"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "rhel-6-els.els:mpfr",
            "rhel-6-els.els:mpfr.src"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2025-06-23T02:48:57+00:00",
          "details": "Apply advisory RHSA-2025:9332 as per vendors instructions.",
          "product_ids": [
            "rhel-7-els.els:mpfr-0:3.1.1-4.el7_9.2",
            "rhel-7-els.els:mpfr-0:3.1.1-4.el7_9.2.src"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2025:9332"
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "version": "2.0",
            "vectorString": "AV:L/AC:H/Au:N/C:N/I:N/A:P",
            "baseScore": 1.2
          },
          "products": [
            "rhel-6-els.els:mpfr",
            "rhel-6-els.els:mpfr-debuginfo",
            "rhel-6-els.els:mpfr-devel",
            "rhel-6-els.els:mpfr.src"
          ]
        },
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "baseScore": 7.0,
            "baseSeverity": "HIGH"
          },
          "products": [
            "rhel-7-els.els:mpfr-0:3.1.1-4.el7_9.2",
            "rhel-7-els.els:mpfr-0:3.1.1-4.el7_9.2.src",
            "rhel-7-els.els:mpfr-debuginfo",
            "rhel-7-els.els:mpfr-devel"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "rhel-6-els.els:mpfr",
            "rhel-6-els.els:mpfr-debuginfo",
            "rhel-6-els.els:mpfr-devel",
            "rhel-6-els.els:mpfr.src",
            "rhel-7-els.els:mpfr-0:3.1.1-4.el7_9.2",
            "rhel-7-els.els:mpfr-0:3.1.1-4.el7_9.2.src",
            "rhel-7-els.els:mpfr-debuginfo",
            "rhel-7-els.els:mpfr-devel"
          ]
        }
      ],
      "title": "buffer overflow in mpfr_strtofr"
    }
  ]
}