CVE-2013-2024: OS Command Injection
Published Oct 31, 2019
·Updated
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
Affected Software
5 affected componentsFixes available
debian/chicken
5.2.0-25.3.0-15.3.0-2
Call-cc Chicken<=4.8.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Event History
Oct 31, 2019
CVE Published
via MITRE·07:57 PM
Data Sourced
via MITRE·07:57 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2013-2024?
CVE-2013-2024 is considered a moderate severity vulnerability because it allows OS command injection which can lead to unauthorized command execution.
2
How do I fix CVE-2013-2024?
To fix CVE-2013-2024, upgrade to Chicken version 4.9.0 or later, as this version addresses the command injection vulnerability.
3
Which software versions are affected by CVE-2013-2024?
CVE-2013-2024 affects Chicken versions earlier than 4.9.0 and specific versions of Debian Linux including 8.0, 9.0, and 10.0.
4
What type of vulnerability is CVE-2013-2024?
CVE-2013-2024 is classified as an OS command injection vulnerability found in the 'qs' procedure of the 'utils' module in Chicken.
5
Is there a workaround for CVE-2013-2024?
There is no official workaround for CVE-2013-2024; upgrading to a patched version is the recommended solution.