Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables.
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Link | Tags |
---|---|
https://github.com/89luca89/distrobox/commit/82a69f0a234e73e447d0ea8c8b3443b84fd31944 | patch |
https://github.com/89luca89/distrobox/issues/1275 | exploit patch issue tracking |