PT-2020-14242 · Miller · Miller

Koernepr

·

Published

2020-09-02

·

Updated

2024-06-15

·

CVE-2020-15167

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Miller versions 5.9.0
Description The issue allows an attacker to execute arbitrary code by placing a malicious .mlrrc file in the working directory, leveraging the configuration file support introduced in version 5.9.0. A fix is ready and will be released.
Recommendations For Miller version 5.9.0, update to version 5.9.1 once it is released to resolve the issue. As a temporary workaround, consider avoiding the use of the configuration file support or restricting access to the working directory to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15167
GHSA-MW2V-4Q78-J2CW
OPENSUSE-SU-2024:11048-1

Affected Products

Miller