debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is shown to the user before execution.)
References
Link | Resource |
---|---|
https://bugs.debian.org/1031267 | Vendor Advisory |
Configurations
Information
Published : 2023-03-05 14:15
Updated : 2023-03-13 09:40
NVD link : CVE-2023-27635
Mitre link : CVE-2023-27635
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
debian
- debmany