Code Execution Vulnerability in Duck Product by Debian
CVE-2016-1239

9.8CRITICAL

Key Information:

Vendor
Debian
Status
Vendor
CVE Published:
19 February 2022

Summary

The Duck product by Debian versions prior to 0.10 contains a vulnerability that allows the improper loading of untrusted code from the current directory, posing significant security risks. This weakness could potentially be exploited by malicious users to execute arbitrary code, leading to data breaches or further compromises within the system.

Affected Version(s)

duck < 0.10

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.