1 results (0.002 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is shown to the user before execution.) • https://bugs.debian.org/1031267 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •