CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
Percentile
81.2%
Tavis Ormandy discovered that xli and xloadimage attempt to
decompress images by piping them through gunzip
or similar decompression tools. Unfortunately, the
unsanitized file name is included as part of the command.
This is dangerous, as in some situations, such as mailcap
processing, an attacker may control the input file name. As a
result, an attacker may be able to cause arbitrary command
execution.