4.6
CVSSv2

CVE-2016-10075

Published: 19/01/2017 Updated: 21/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to execute arbitrary code via a crafted repo with a malicious git log in the current working directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tqdm project tqdm 4.10

tqdm project tqdm 4.4.1

Vendor Advisories

Debian Bug report logs - #849632 tqdm: CVE-2016-10075: insecure use of git Package: src:tqdm; Maintainer for src:tqdm is Sandro Tosi <morph@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 29 Dec 2016 10:09:01 UTC Severity: normal Tags: security, upstream Found in version tqdm/4100-1 F ...