Command Injection via eval in Debian-goodies 0.88.1
CVE-2023-27635 Published on March 5, 2023

debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is shown to the user before execution.)

NVD


Products Associated with CVE-2023-27635

Want to know whenever a new CVE is published for Debian Debmany? stack.watch will email you.

 

Exploit Probability

EPSS
0.08%
Percentile
23.82%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.