Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-29924 Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T03:47:12.960Z

Reserved: 2021-10-25T00:00:00

Link: CVE-2021-42969

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-13T12:15:08.207

Modified: 2024-11-21T06:28:20.513

Link: CVE-2021-42969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.