Code Execution Vulnerability in Duck Product by Debian
CVE-2016-1239
9.8CRITICAL
Summary
The Duck product by Debian versions prior to 0.10 contains a vulnerability that allows the improper loading of untrusted code from the current directory, posing significant security risks. This weakness could potentially be exploited by malicious users to execute arbitrary code, leading to data breaches or further compromises within the system.
Affected Version(s)
duck < 0.10
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved