CVE-2014-6311: Debian Linux

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Vanderbilt Adaptive Communication Environment: up to and including 6.2.6; version 6.2.7 only

Published 2019-11-22. Last modified 2026-06-17.