PT-2024-23089 · Distrobox · Distrobox

Xoicho

·

Published

2024-03-21

·

Updated

2025-06-17

·

CVE-2024-29864

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Distrobox versions prior to 1.7.0.1
Description The issue allows attackers to execute arbitrary code via command injection into exported executables.
Recommendations For versions prior to 1.7.0.1, update to version 1.7.0.1 or later to resolve the issue.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-29864

Affected Products

Distrobox