Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-27629

Опубликовано: 28 июн. 2024
Источник: debian
EPSS Низкий

Описание

An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dcm2niixfixed1.0.20240202-1package
dcm2niixfixed1.0.20220720-1+deb12u1bookwormpackage
dcm2niixignoredbullseyepackage

Примечания

  • https://github.com/rordenlab/dcm2niix/pull/789

EPSS

Процентиль: 29%
0.00103
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 1 года назад

An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.

CVSS3: 7.8
nvd
больше 1 года назад

An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.

CVSS3: 7.8
github
больше 1 года назад

An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.

EPSS

Процентиль: 29%
0.00103
Низкий
Уязвимость CVE-2024-27629