Arbitrary Command Execution in Debian Goodies by Debian
CVE-2023-27635
7.8HIGH
What is CVE-2023-27635?
The debmany tool in debian-goodies version 0.88.1 is susceptible to a vulnerability that allows attackers to execute arbitrary shell commands. This is made possible due to an insecure eval call when processing a crafted .deb file, which may expose the command execution path to the user prior to execution, leading to potential exploitation.