10
CVSSv2

CVE-2016-1253

Published: 05/12/2017 Updated: 20/12/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The most package in Debian wheezy prior to 5.0.0a-2.2, in Debian jessie prior to 5.0.0a-2.3+deb8u1, and in Debian unstable prior to 5.0.0a-3 allows remote malicious users to execute arbitrary commands via shell metacharacters in the name of an LZMA-compressed file.

Vulnerable Product Search on Vulmon Subscribe to Product

debian most

Vendor Advisories

Debian Bug report logs - #848132 most: CVE-2016-1253: shell injection attack using LZMA-compressed files Package: most; Maintainer for most is Benjamin Mako Hill <mako@debianorg>; Source for most is src:most (PTS, buildd, popcon) Reported by: Alberto Garcia <berto@igaliacom> Date: Wed, 14 Dec 2016 12:51:01 UTC Sev ...