CVE-2023-27635: High severity debian vulnerability
Published Mar 5, 2023
·Updated
debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is shown to the user before execution.)
Affected Software
5 affected componentsFixes available
debian/debian-goodies<=0.84, <=0.87, <=0.88.1
ubuntu/debian-goodies<0.84ubuntu0.1
0.84ubuntu0.1
ubuntu/debian-goodies<0.87ubuntu1.1
0.87ubuntu1.1
ubuntu/debian-goodies<0.88.1ubuntu1.2
0.88.1ubuntu1.2
Debian debmany=0.88.1
Event History
Mar 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 25, 2024
Data Sourced
via Launchpad·05:32 PM
Description
Frequently Asked Questions
1
What is CVE-2023-27635?
CVE-2023-27635 is a vulnerability in debian-goodies 0.88.1 that allows attackers to execute arbitrary shell commands.
2
How can the CVE-2023-27635 vulnerability be exploited?
The CVE-2023-27635 vulnerability can be exploited by sending a crafted .deb file to debian-goodies 0.88.1, which triggers an eval call and allows the execution of arbitrary shell commands.
3
What is the severity of CVE-2023-27635?
The severity of CVE-2023-27635 is high, with a severity score of 7.8.
4
Which version of debian-goodies is affected by CVE-2023-27635?
CVE-2023-27635 affects debian-goodies version 0.88.1.
5
Is there a fix for CVE-2023-27635?
Yes, upgrading to a fixed version of debian-goodies is recommended to fix CVE-2023-27635.