NA

CVE-2023-27635

Published: 05/03/2023 Updated: 13/03/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

debmany in debian-goodies 0.88.1 allows malicious users to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is shown to the user before execution.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debmany 0.88.1

Vendor Advisories

Debian Bug report logs - #1031267 debmany: CVE-2023-27635: shell injection Package: debian-goodies; Maintainer for debian-goodies is Javier Fernández-Sanguino Peña <jfs@debianorg>; Source for debian-goodies is src:debian-goodies (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@jwilknet> Date: Tue, 14 Feb 2023 ...