Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jimrandomh

#40198of 53,622
6.8Total CVSS
Vulnerabilities · 1
PT-2013-6255
6.8
2013-12-05
Ack · Ack · CVE-2013-7069
**Name of the Vulnerable Software and Affected Versions** ack versions 2.00 through 2.11 02 **Description** The issue allows remote attackers to execute arbitrary code via certain options in a .ackrc file in a directory to be searched. Specifically, the options `--pager`, `--regex`, and `--output` are vulnerable. **Recommendations** For ack versions 2.00 through 2.11 02, consider removing or restricting the use of the `--pager`, `--regex`, and `--output` options in .ackrc files until a patch is available. Avoid using these options in directories that may be searched by untrusted users.