Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-10224

Опубликовано: 19 нояб. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.3

Описание

Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().

РелизСтатусПримечание
devel

not-affected

1.35-2
esm-apps/bionic

released

1.24-1ubuntu0.1~esm1
esm-apps/focal

released

1.27-1ubuntu0.1~esm1
esm-apps/xenial

released

1.20-1ubuntu0.1~esm1
focal

ignored

end of standard support, was needed
jammy

released

1.31-1ubuntu0.1
noble

released

1.35-1ubuntu0.24.04.1
oracular

released

1.35-1ubuntu0.24.10.1
plucky

not-affected

1.35-2
upstream

needed

Показывать по

EPSS

Процентиль: 62%
0.00432
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
9 месяцев назад

Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().

CVSS3: 5.3
nvd
9 месяцев назад

Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().

CVSS3: 5.3
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 5.3
debian
9 месяцев назад

Qualys discovered that if unsanitized input was used with the library ...

oracle-oval
3 месяца назад

ELSA-2025-7350: perl-Module-ScanDeps security update (MODERATE)

EPSS

Процентиль: 62%
0.00432
Низкий

5.3 Medium

CVSS3