Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39819
HistoryMar 18, 2023 - 1:15 a.m.

Command Injection

2023-03-1801:15:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
1
command injection
update.c
attacker manipulation
os command injection
liferea

7.6 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.2%

liferea is vulnerable to Command Injection. The vulnerability exists in the update_job_run function of update.c, which allows an attacker to manipulate of the argument source with the input |date >/tmp/bad-item-link.txt leads to os command injection

7.6 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.2%