7.5
CVSSv2

CVE-2008-1568

Published: 31/03/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

comix 3.6.4 allows malicious users to execute arbitrary commands via a filename containing shell metacharacters that are not properly sanitized when executing the rar, unrar, or jpegtran programs.

Vulnerable Product Search on Vulmon Subscribe to Product

comix comix 3.6.4

Vendor Advisories

Debian Bug report logs - #462840 comix: insufficient escaping on shell calls for rar archives/jpegtran Package: comix; Maintainer for comix is Emfox Zhou <emfox@debianorg>; Source for comix is src:comix (PTS, buildd, popcon) Reported by: hhaamu@gmailcom Date: Sun, 27 Jan 2008 19:33:01 UTC Severity: grave Tags: security ...