← volver
CVE-2020-15167

Arbitrary code execution via configuration file in Miller

CVSS 8.2 HIGHEPSS 0.4%CWE-94
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.2EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
02 sep 2020Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to run arbitrary code by placing a malicious `.mlrrc` file in the working directory. See linked GitHub Security Advisory for complete details. A fix is ready and will be released as Miller 5.9.1.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Productos afectados
johnkerl · miller