7.5

CVE-2005-0638

xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.

Data is provided by the National Vulnerability Database (NVD)
XliXli Version1.14
XliXli Version1.15
XliXli Version1.16
XliXli Version1.17
AltlinuxAlt Linux Version2.3 Editioncompact
AltlinuxAlt Linux Version2.3 Editionjunior
SuseSuse Linux Version1.0
SuseSuse Linux Version2.0
SuseSuse Linux Version3.0
SuseSuse Linux Version4.0
SuseSuse Linux Version4.2
SuseSuse Linux Version4.3
SuseSuse Linux Version4.4
SuseSuse Linux Version4.4.1
SuseSuse Linux Version5.0
SuseSuse Linux Version5.1
SuseSuse Linux Version5.2
SuseSuse Linux Version5.3
SuseSuse Linux Version6.0
SuseSuse Linux Version6.1
SuseSuse Linux Version6.1 Updatealpha
SuseSuse Linux Version6.2
SuseSuse Linux Version6.3
SuseSuse Linux Version6.3 Editionppc
SuseSuse Linux Version6.3 Updatealpha
SuseSuse Linux Version6.4
SuseSuse Linux Version6.4 Editioni386
SuseSuse Linux Version6.4 Editionppc
SuseSuse Linux Version6.4 Updatealpha
SuseSuse Linux Version7.0
SuseSuse Linux Version7.0 Editioni386
SuseSuse Linux Version7.0 Editionppc
SuseSuse Linux Version7.0 Editionsparc
SuseSuse Linux Version7.0 Updatealpha
SuseSuse Linux Version7.1
SuseSuse Linux Version7.1 Editionspa
SuseSuse Linux Version7.1 Editionsparc
SuseSuse Linux Version7.1 Editionx86
SuseSuse Linux Version7.1 Updatealpha
SuseSuse Linux Version7.2
SuseSuse Linux Version7.2 Editioni386
SuseSuse Linux Version7.3
SuseSuse Linux Version7.3 Editioni386
SuseSuse Linux Version7.3 Editionppc
SuseSuse Linux Version7.3 Editionsparc
SuseSuse Linux Version8.0
SuseSuse Linux Version8.0 Editioni386
SuseSuse Linux Version8.1
SuseSuse Linux Version8.2
SuseSuse Linux Version9.0
SuseSuse Linux Version9.0 Editionx86_64
SuseSuse Linux Version9.1
SuseSuse Linux Version9.1 Editionx86_64
SuseSuse Linux Version9.2
SuseSuse Linux Version9.2 Editionx86_64
SuseSuse Linux Version9.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.39% 0.844
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P