CVE-2024-10224
Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().
- Affected products
- Almalinux, Astra Linux, Linuxmint, Modules::Scandeps, Red Hat, Red Os, Rocky Linux, Ubuntu
- Rschupp Modules\:\:scandeps
- < 1.36
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 8.6% (95th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2024-11-19
CVE-2024-10224 at NVD
2 known exploits for CVE-2024-10224
Proof-of-concept code and exploit modules indexed by Sploitus