Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4mcm-8fr8-677g

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

comix 3.6.4 allows attackers to execute arbitrary commands via a filename containing shell metacharacters that are not properly sanitized when executing the rar, unrar, or jpegtran programs.

comix 3.6.4 allows attackers to execute arbitrary commands via a filename containing shell metacharacters that are not properly sanitized when executing the rar, unrar, or jpegtran programs.

EPSS

Процентиль: 73%
0.00793
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 17 лет назад

comix 3.6.4 allows attackers to execute arbitrary commands via a filename containing shell metacharacters that are not properly sanitized when executing the rar, unrar, or jpegtran programs.

redhat
больше 17 лет назад

comix 3.6.4 allows attackers to execute arbitrary commands via a filename containing shell metacharacters that are not properly sanitized when executing the rar, unrar, or jpegtran programs.

nvd
больше 17 лет назад

comix 3.6.4 allows attackers to execute arbitrary commands via a filename containing shell metacharacters that are not properly sanitized when executing the rar, unrar, or jpegtran programs.

debian
больше 17 лет назад

comix 3.6.4 allows attackers to execute arbitrary commands via a filen ...

EPSS

Процентиль: 73%
0.00793
Низкий

Дефекты

CWE-20