PT-2013-6255 · Ack+1 · Ack+1
Jimrandomh
·
Publicado
2013-12-05
·
Atualizado
2024-06-15
·
CVE-2013-7069
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ack versions 2.00 through 2.11 02
Description
The issue allows remote attackers to execute arbitrary code via certain options in a .ackrc file in a directory to be searched. Specifically, the options
--pager, --regex, and --output are vulnerable.Recommendations
For ack versions 2.00 through 2.11 02, consider removing or restricting the use of the
--pager, --regex, and --output options in .ackrc files until a patch is available. Avoid using these options in directories that may be searched by untrusted users.Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Ack