Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2024-27629
HistoryJun 28, 2024 - 7:15 p.m.

CVE-2024-27629

2024-06-2819:15:05
Debian Security Bug Tracker
security-tracker.debian.org
1
dc2niix
local attacker
arbitrary code
file names
system call
compression
unix

8 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.

8 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

Related for DEBIANCVE:CVE-2024-27629