Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-58266

Опубликовано: 27 июл. 2025
Источник: debian
EPSS Низкий

Описание

The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-shlexfixed1.3.0-1package
rust-shlexno-dsabookwormpackage
rust-shlexno-dsabullseyepackage
rust-shlexno-dsabusterpackage

Примечания

  • https://rustsec.org/advisories/RUSTSEC-2024-0006.html

  • https://github.com/comex/rust-shlex/security/advisories/GHSA-r7qv-8r2h-pg27

EPSS

Процентиль: 14%
0.0006
Низкий

Связанные уязвимости

CVSS3: 3.2
ubuntu
4 месяца назад

The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.

CVSS3: 3.2
redhat
4 месяца назад

The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.

CVSS3: 3.2
nvd
4 месяца назад

The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.

CVSS3: 3.2
msrc
3 месяца назад

The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.

suse-cvrf
3 месяца назад

Security update for rav1e

EPSS

Процентиль: 14%
0.0006
Низкий