An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T00:34:52.485Z

Reserved: 2024-02-26T00:00:00

Link: CVE-2024-27629

cve-icon Vulnrichment

Updated: 2024-07-16T17:46:11.156Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-28T19:15:05.243

Modified: 2024-11-21T09:04:50.130

Link: CVE-2024-27629

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.