Related Vulnerabilities: CVE-2016-8606  

It was reported that the REPL server is vulnerable to the HTTP inter-protocol attack. This constitutes a remote code execution vulnerability for developers running a REPL server that listens on a loopback device or private network. Applications that do not run a REPL server, as is usually the case, are unaffected.

Severity High

Remote Yes

Type Arbitrary code execution

Description

It was  reported that the REPL server is vulnerable to the HTTP inter-protocol attack. This constitutes a remote code execution vulnerability for developers running a REPL server that listens on a loopback device or private network. Applications that do not run a REPL server, as is usually the case, are unaffected.

AVG-47 guile 2.0.12-1 2.0.13-1 High Fixed

16 Oct 2016 ASA-201610-10 AVG-47 guile High multiple issues

https://lists.gnu.org/archive/html/info-gnu/2016-10/msg00009.html