Arbitrary Code Execution Vulnerability in xzgrep by Tukaani
CVE-2015-4035
7.8HIGH
What is CVE-2015-4035?
The xzgrep utility from Tukaani, specifically versions 5.2.x prior to 5.2.0 and 5.0.0, is susceptible to an arbitrary code execution vulnerability. This flaw arises from improper handling of file names containing semicolons, enabling remote attackers to execute arbitrary code if a user processes a specially crafted file name using the xzgrep command.