Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11622
HistoryJan 15, 2019 - 9:05 a.m.

Arbitrary Code Execution

2019-01-1509:05:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.228 Low

EPSS

Percentile

96.5%

setroubleshoot is vulnerable to arbitrary code execution. Files names that are supplied in a shell command look-up for RPMs associated with access violation reports are not sanitized, allowing an attacker to enter shell metacharacters in a file name and subsequently executing arbitrary commands on the system.