1 results (0.003 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

10 Dec 2022 — egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file. egg-compile.scm en CHICKEN 5.x anterior a 5.3.1 permite la ejecución arbitraria de comandos del Sistema Operativo durante la instalación del paquete mediante caracteres de escape en un archivo .egg. • https://code.call-cc.org/cgi-bin/gitweb.cgi?p=chicken-core.git%3Ba=blobdiff%3Bf=NEWS%3Bh=54888afff09353093453673c407cabfe76a5ce77%3Bhp=a3fd88a892f82c8353267f50509d018bbb1934b9%3Bhb=670478435a982fc4d1f001ea08669f53d35a51cd%3Bhpb=a08f8f548d772ef410c672ba33a27108d8d434f3 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •