scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name.
2017-07-25T18:29:00.557
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | tukaani | xz | ≤ 4.999.9 | Yes |
Operating System | redhat | enterprise_linux | 5.0 | No |
Operating System | redhat | enterprise_linux | 6.0 | No |